Getting Data In

How to increase logs retention period?

islam
Explorer

Hi,

we are asked to increase our retention period of splunk logs to 1 year.

we need to put our data to be searchable for 1 year.

i'm very confused about hot, warm and cold data, are all of them is searchable or cold data is not searchable?

how can we configure this retenion period?

 

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma

islam
Explorer

Thank you so much, it's a very useful article.

also i have one question: the values of frozenTimePeriodInSecs and maxTotalDataSizeMB  should be put under every index or just one time at the beginning of indexes.cong file ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

If those are same for all your indexes then you can put those on default stanza and if not then you should add those to the individual indexes. 

0 Karma

islam
Explorer

can i put specific period for hot and cold data, like hot data to be 6 months and cold data to be 6 moths also ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

No, only cold period can defined as seconds. Hot/warm is defined by bucket count and/or size of homePath. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...