Getting Data In

How to configure Splunk to keep _internal data longer than 30 days?

ralphw_SAIC
Path Finder

For some reason _internal is only available for the last 30 days even though it has not reached its max size limit stated in indexes.conf. Is there any way to increase the retention time for _internal and if so where?

0 Karma
1 Solution

anshu
Path Finder

By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.

---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000

View solution in original post

anshu
Path Finder

By default, this index is configured to freeze or "archive" data after 30 days. You can customize the "frozenTimePeriodInSecs" attribute for the index. Just replace the value below to the retention period you want in an indexes.conf file in $SPLUNK_HOME/etc/system/local/ or in $SPLUNK_HOME/etc/apps/< app_name > if deploying the configuration via an app.

---indexes.conf---
[_internal]
frozenTimePeriodInSecs = 2592000

ralphw_SAIC
Path Finder

I have a global of 90days, so just assumed it included _internal.

Thanks for the quick response.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...