Deployment Architecture

Is there any practical/inexpensive way to do long time data storage in Splunk Cloud?

hettervik
Builder

Hi,

I've looked around in the documentation for how to set an archiving policy in Splunk Cloud, but I haven't found an answer yet. I know that the document "Safeguarding Customer Data in Splunk Cloud" talk about archiving, but in this paper they call it archiving when data is rolled from hot to warm. I want to to know if there's a way to roll to frozen in Splunk Cloud, and if so, what's the price of storing data this way compared to storing data in warm buckets?

0 Karma
1 Solution

pgreer_splunk
Splunk Employee
Splunk Employee

Best bet is to work with your rep (if you don't have one, let me know area/company and I'll help you out there). There are several levels of storage, Ephemeral, Elastic Block and S3 (Simple Storage Service). Each have their pros/cons/costs/speeds/feeds/blahblahblah.

Bottom line is yes, there are options for archiving. How much data and to where and what would be the costs have many factors and considerations. Each use case is unique and each should be evaluated as to what is best for your use case.

View solution in original post

0 Karma

pgreer_splunk
Splunk Employee
Splunk Employee

Best bet is to work with your rep (if you don't have one, let me know area/company and I'll help you out there). There are several levels of storage, Ephemeral, Elastic Block and S3 (Simple Storage Service). Each have their pros/cons/costs/speeds/feeds/blahblahblah.

Bottom line is yes, there are options for archiving. How much data and to where and what would be the costs have many factors and considerations. Each use case is unique and each should be evaluated as to what is best for your use case.

0 Karma

hettervik
Builder

Thanks for your answer! So, if we use one of these storage types, is the data still accessible from Splunk Cloud? I mean, Splunk can set it up for me so that when data is rolled to e.g. cold it is moved from the indexer in the cloud to some data storing service that can store bigger amounts of data?

Also, I see that it's possible to buy storage increments of 500 GB for Splunk Cloud, but I'm guessing this is rather expensive compared to moving the cold/frozen data to e.g. a local storage.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...