I want to set up the retention policy for our logs (18 months). I have edited the indexes.conf to specify frozenTimePeriodInSecs however as per splunk documentation this setting, which we have set up as well: maxTotalDataSizeMB takes precedence over frozenTimePeriodInSecs . Is there any work around to leave the TotalDataSizeMB set up to a specific value and keep the logs only for 18 months regardless the TotalDataSize? Thanks for help Dawid M
... View more