Splunk Enterprise

Need to dseign a search to retrieve data on cold db

imamsumtotal
Engager

Hi

We have deployed a flash blade to use it for cold db storage. As testing purpose we have configured cold buckets for a single index. We can see data moving from indexers(hot) to the flash blade (cold).  Confirmed the same using dbinspect. Need to check if i can be able to search data under cold db without any issues. Can someone please help with sample searches that can access the cold storage data so that i could analyse the search results. Data from hot buckets will move to cold once 200 gb exceeded. Thanks in advance.

Environment:Splunk Enterprise

Indexer cluster with 3 peers

Labels (2)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Just use “all time” for time with this index. 

r. Ismo

View solution in original post

isoutamo
SplunkTrust
SplunkTrust

Just use “all time” for time with this index. 

r. Ismo

imamsumtotal
Engager

Thanks.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...