1. Is this query correct to know how long it is configured to go to frozen? | rest / services / data / indexes | fields title froz * | rename title as index -- Yes SPL is correct 2. If I need it not to store the logs for 6 years, which is the value that I see by default, and I need it to store the logs for 6 months, understanding that when the log reaches 6 months it would go to a frozen state and splunk would begin to eliminate the older data. -- https://docs.splunk.com/Documentation/Splunk/8.1.1/Indexer/Setaretirementandarchivingpolicy The maxTotalDataSizeMB and frozenTimePeriodInSecs attributes in indexes.conf help determine when buckets roll from cold to frozen. 3. I should create a file called indexes.conf in the "local" folder and set the value frozenTimePeriodInSecs = 15778800 -- Yes , 15778800 (seconds) means something near to 6 months (60*60*24*180) and for exact value is 15552000 (considering 30 days in each month). b Should I go to the bin and restart the splunk service for it to take the changes? -- Yes, if you are on "standalone infra" Splunk restart required and if you are on a "indexer cluster" a configuration push with rolling restart of all the peer nodes required. 4. Would this change immediately erase logs that are already 6 months old in seconds? or does it start from this moment? -- Its not very immediate, based on your infra may take 2-10 min (again its based on your Splunk infra).
... View more