Splunk Search

search results expiring

gcusello
SplunkTrust
SplunkTrust

Hi at all,

I noted a strange thing:

in a splunk 8.2.2 with ES 6.6.2, the customer scheduled some daily reports with a time period of 24 hours and I found that the dispatch.ttl for these reports has the default value of "2p", that should mean 2 days.

But The customer also found that the search results are maintained on the Splunk server for around 30 days.

Can anyone help me to understand the reasons of this behaviour and where to find the problem?

and how to reduce this disk space occupation?

Ciao.

Giuseppe

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...