Deployment Architecture

Change frozenTimePeriodInSecs of an existing indexes

GaetanVP
Contributor

Hello Splunkers,

I would like to change the value of frozenTimePeriodInSecs for one of my existing indexes.

What should I be careful of ? Juste change the value on my Master Node and push the new bundle to my Indexers ? 

Also since my frozenTimePeriodInSecs will be lower than some of my bucket indexes, those events will be automatically rolled to frozen ? 

Thanks a lot !
GaetanVP

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

As always when changing frozenTimePeriodInSecs, make sure you have the correct value.  Leaving out a digit or doing the maths wrong may result in unintended data deletion.

That said, you have the right idea.  Change the setting on the Cluster Manager and push the bundle.  The indexers will then freeze any buckets that have no data newer than the new frozenTimePeriodInSecs value.

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust

Hi

one old post to answering your next question “Why I still have older data than….” 😉 It contains also one old but still mostly valid conf presentation.

https://community.splunk.com/t5/Deployment-Architecture/When-will-my-buckets-roll/m-p/579468 

r. Ismo

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...