...isk space is allocated
At the current rate of ingestion, what would the retention be if we used 100% of all allocated space available for the index. eg 360 days
What is limiting our retention - i...
Hi Team,
We have deployed Splunk Cloud in our environment. And by default i believe we have been subscribed for 90 days of retention. i.e. 90 days of data would be available in Splunk for all i...
Hi , I implemented the splunk index retention policy for 6 months and it applies suddenly , i got a lot of free space for the data which is in cold location but my data which is in hot bucket and w...
We have already configured a retention policy of an index which send data to frozen directory after maxDataVolume size reaches (2184 days).Now i want to reduce the retention policy for that index o...
Hi , i am currently setting up the retention policy of an index for data roll over to frozen but i am currently setting data roll over to frozen after 6 months but i am intrested to move data from h...
...rom 2 firewalls. The logs are only audit / management related, and these need to be sent to a sperate server for compliance (hence splunk). I want to configure a retention policy where this data i...
Hello all,
I'm trying to setup the following retention policy:
15 days of events to be searchable (hot/warm/cold - it doesn't matter) + 15 days of data to be frozen (archived). So always I w...
...set up in the warm buckets that it never rolls over to cold. I am trying to create a dataretention policy that will hopefully better allow us to keep our data backed up. We have a file system back t...
I am fairly limited knowledge on buckets. I have one single storage drive available to me of 2 TB. And the retention policy is 18 months. The Splunk indexer is capturing the Windows logs and data v...
Hi, may i know how to configure Splunk to only retain a rolling window of 3 months of logs data?
I'm completely new to the retention policy so any help or step by step instruction will be g...