Deployment Architecture

Delete Indexed data

eantonio
Path Finder

I want to know when data are moved from Hot to Warm bucket? does it depend on the date it was indexed in Splunk? or does it depend on the size of the Hot Bucket setting? where do i modify this setting?
I saw on the documentation that the maximum size for an index is 500,000MB. Will Splunk only delete data when it reach the 500,000MB limit? or will it still delete the data as long as it reached the Frozen bucket stage? what usually is the time frame before data are deleted from Splunk?

Tags (3)
0 Karma
1 Solution
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...