Deployment Architecture

Index Retention

nawazns5038
Builder

Hi,

If I just mention frozenTimePeriodInSecs as 30 days , how does Splunk roll the buckets exactly so that the data gets deleted in 30 days ?

Will adding the parameters like homePath.maxDataSizeMB , coldPath.maxDataSizeMB effect the rolling of buckets ?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Retention time refers to the newest event in a bucket. If a bucket typically holds 7 days of data, for example, then it will not be deleted until it is 37 days old because the last event written to it must be at least 30 days old.

The size constraints are considered separately. If an index reaches its size limit, the oldest buckets will be deleted until the index is within the size limit. This means buckets may be frozen before 30 days.

---
If this reply helps you, Karma would be appreciated.

nawazns5038
Builder

Thanks for the answer @richgalloway,

But the parameter frozenTimePeriodInSecs applies to cold buckets , there are bucket stages in between. How does Splunk organize the rolling so that data falls into the cold and retention is applied

What if the data volume is low and is present only in the hot and warm buckets itself and didn't come into cold still and the period has exceeded 30 days ?
So the retention policy will not apply in this case ??

0 Karma

ddrillic
Ultra Champion

frozenTimePeriodInSecs is actually the time from creation to frozen, regardless of the stages in between.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...