We are actually being told our retention is beyond normal standards. Currently our Splunk reps are telling us we really should only be keeping data around for something like 7 to 14 days searchable and a lot shorter frozen storage point of view. In my mind, if we had a bigger investigation that need to be done on frozen storage as we have it, something like restoring data to a summary index of sorts would be better than rehydrating into our standard indexes. However, I haven't personally done a lot of work with that. I think then smaller request wouldn't be so bad. However, that 6 hour wait time is rough and can definitely slow down research efforts.
... View more