I am working on a project in Splunk Cloud and one of the questions I wanted to iron out was how data is stored and refreshed in Splunk. The data I am analyzing is based on real-time and I am looking for active issues and how long they have been that way for. For example, if an issue has been recurring for three minutes (just an example, could be a longer or shorter time frame), then how long will the data stay in the system for? I apologize if this is vague, but I am trying to wrap my head around how this works.
Thank you.
... View more