Hello!
I'm new to Splunk and just getting my head around it all.
Our company is already using Splunk and we are considering using it on an apache server to gather web statistics in a similar fashion to AWstats.
We have enabled a log rotation on our server and we have 1 month worth of logs that is rotated. My concern is that once the apache server deletes the logs older then one month then I assume we will no longer be able to be search on that old information through splunk.
Ideally I would like 6-12 months worth of data. We have already racked up 645,000 events in a single month.
If we saved our logs somewhere else and got splunk to review our 6-12 months of data we would be going over a few million events. If splunk the right tool for this job? Can it handle that number of events? Or is it mostly made for short term log analysis?
... View more