Deployment Architecture

Is there any practical/inexpensive way to do long time data storage in Splunk Cloud?

hettervik
Builder

Hi,

I've looked around in the documentation for how to set an archiving policy in Splunk Cloud, but I haven't found an answer yet. I know that the document "Safeguarding Customer Data in Splunk Cloud" talk about archiving, but in this paper they call it archiving when data is rolled from hot to warm. I want to to know if there's a way to roll to frozen in Splunk Cloud, and if so, what's the price of storing data this way compared to storing data in warm buckets?

0 Karma
1 Solution

pgreer_splunk
Splunk Employee
Splunk Employee

Best bet is to work with your rep (if you don't have one, let me know area/company and I'll help you out there). There are several levels of storage, Ephemeral, Elastic Block and S3 (Simple Storage Service). Each have their pros/cons/costs/speeds/feeds/blahblahblah.

Bottom line is yes, there are options for archiving. How much data and to where and what would be the costs have many factors and considerations. Each use case is unique and each should be evaluated as to what is best for your use case.

View solution in original post

0 Karma

pgreer_splunk
Splunk Employee
Splunk Employee

Best bet is to work with your rep (if you don't have one, let me know area/company and I'll help you out there). There are several levels of storage, Ephemeral, Elastic Block and S3 (Simple Storage Service). Each have their pros/cons/costs/speeds/feeds/blahblahblah.

Bottom line is yes, there are options for archiving. How much data and to where and what would be the costs have many factors and considerations. Each use case is unique and each should be evaluated as to what is best for your use case.

0 Karma

hettervik
Builder

Thanks for your answer! So, if we use one of these storage types, is the data still accessible from Splunk Cloud? I mean, Splunk can set it up for me so that when data is rolled to e.g. cold it is moved from the indexer in the cloud to some data storing service that can store bigger amounts of data?

Also, I see that it's possible to buy storage increments of 500 GB for Splunk Cloud, but I'm guessing this is rather expensive compared to moving the cold/frozen data to e.g. a local storage.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...