@Lucas K @mmodestino_splunk
Thanks for the reply. so as I understand
1> so even if the data in the buckets is older than 365 days if the data in that same bucket is new it wont rioll the bucket to frozen, is this correct?
2> like np_aap we have AAP_PROD index for prod index and it has very heavy volumes of data(license usage report says avg of 150gb, but this above images shows it only adding 20gb per index, we have 4 indexers)
this shows data since 2002 / 365 (see image)
for AAP_PROD index I see data from march 9th till today. March 9th was the day when we built this new clustered infrastructure.
Freeze Async Message in Internal Log looks like this, dont know what to search for ...
08-20-2016 23:32:32.228 -0700 INFO StreamedSearch - Streamed search connection terminated: search_id=remote_p01apl.ent.com_1471761143.19590_12B16A82-0C9F-415D-A8A8-AEEB96B9AA2B, server=p01apl.ent.com, active_searches=6, elapsedTime=8.753, search='litsearch index=_internal idex=aap_prod "Freeze Async" | fields keepcolorder=t "*" "_bkt" "_cd" "_si" "host" "index" "linecount" "source" "sourcetype" "splunk_server" | remotetl nb=300 et=2147483647.000000 lt=0.000000 remove=true max_count=1000 max_prefetch=100', savedsearch_name=""
Thanks again for looking into this.
... View more