Splunk Dev

Splunk Cloud Retention Policy

anandhalagaras1
Contributor

Hi Team,

We have deployed Splunk Cloud in our environment. And by default i believe we have been subscribed for 90 days of retention. i.e. 90 days of data would be available in Splunk for all indexes. This is how it works.

So recently we have increased the retention policy from 90 to 180 days by mid of Jan 2020 so will all the old 180 days of data will be there in Splunk Cloud and it would be searchable? Can you kindly let me know how it works with an example please.

For example:

I have changed the retention policy from 90 to 180 days on Jan 15th 2020 so will it be all the older data would be available in Splunk and it will be searchable. i.e. From July 15th 2019 all data would be available till date for all index and will it be searchable?

Kindly let me know how it works.

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If the retention period is 90 days then anything older than 90 days is deleted. Extending the retention period does not (and can not) undelete old data. The new retention period applies to buckets currently searchable.

For example, if the retention period is 90 days on 14 Jan 20 then the oldest event would be dated 16 Oct 19. If the retention period is changed to 180 days on 15 Jan 20 then the oldest events will still be dated 16 Oct 19, but it will remain searchable until 13 Apr 20.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the retention period is 90 days then anything older than 90 days is deleted. Extending the retention period does not (and can not) undelete old data. The new retention period applies to buckets currently searchable.

For example, if the retention period is 90 days on 14 Jan 20 then the oldest event would be dated 16 Oct 19. If the retention period is changed to 180 days on 15 Jan 20 then the oldest events will still be dated 16 Oct 19, but it will remain searchable until 13 Apr 20.

---
If this reply helps you, Karma would be appreciated.
0 Karma

anandhalagaras1
Contributor

Thank you for your valuable explanation

0 Karma

anandhalagaras1
Contributor

Kindly help to respond.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...