Hi somesoni2,
thanks for reply. But in this case everyday bucket rolled, in this case i have always evailable data searchable for latest 6 months. Customer wants a windows of events available for 6 months.
Example:
If today is 13 April logs must be available until 13 October, tomorrow that is 14 April logs should be available on Splunk until 14 October...and so on!
This should work for a window of 6 months.
Thanks.
... View more