Installation

How should I set my retention policy based on my daily license size?

mprreddy51
Explorer

Hi Experts,

I have a question regarding license and retention policy.

For example, I have a license of 1GB/day and my server is generating logs approximately 5MB/day. How many days can I set my retention policy on this?

Thanks

-P

Labels (1)
0 Karma
1 Solution

somesoni2
Revered Legend

The license limit is the amount of data that you can index daily. The retention period is how long you want your indexed data to be available in Splunk (for search) and affected by the storage capacity on the Indexers. So, find out how much disk storage you've on your indexes and set the retention period accordingly. This will help http://docs.splunk.com/Documentation/Splunk/6.4.3/Capacity/HowSplunkcalculatesdiskstorage

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Licensing and retention are like comparing apples to oranges.. Licensing is constrained by how much data you index per day while retention is constrained by how big your storage is. So if you had a 1TB drive and only indexed 1GB/day (Using 1 index as an example) then you could set up each bucket to retain 200GB before rolling it to the next bucket which is a bit overkill. Now if you had a 2GB drive then you would want to decrease the size of each bucket to prevent the drive from filling up.. Unless you specify a frozen bucket archive, it will be deleted so you can keep indexing new data.

So to answer your question, it would depend on your available drive space..

0 Karma

somesoni2
Revered Legend

The license limit is the amount of data that you can index daily. The retention period is how long you want your indexed data to be available in Splunk (for search) and affected by the storage capacity on the Indexers. So, find out how much disk storage you've on your indexes and set the retention period accordingly. This will help http://docs.splunk.com/Documentation/Splunk/6.4.3/Capacity/HowSplunkcalculatesdiskstorage

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...