Installation

How should I set my retention policy based on my daily license size?

mprreddy51
Explorer

Hi Experts,

I have a question regarding license and retention policy.

For example, I have a license of 1GB/day and my server is generating logs approximately 5MB/day. How many days can I set my retention policy on this?

Thanks

-P

Labels (1)
0 Karma
1 Solution

somesoni2
Revered Legend

The license limit is the amount of data that you can index daily. The retention period is how long you want your indexed data to be available in Splunk (for search) and affected by the storage capacity on the Indexers. So, find out how much disk storage you've on your indexes and set the retention period accordingly. This will help http://docs.splunk.com/Documentation/Splunk/6.4.3/Capacity/HowSplunkcalculatesdiskstorage

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Licensing and retention are like comparing apples to oranges.. Licensing is constrained by how much data you index per day while retention is constrained by how big your storage is. So if you had a 1TB drive and only indexed 1GB/day (Using 1 index as an example) then you could set up each bucket to retain 200GB before rolling it to the next bucket which is a bit overkill. Now if you had a 2GB drive then you would want to decrease the size of each bucket to prevent the drive from filling up.. Unless you specify a frozen bucket archive, it will be deleted so you can keep indexing new data.

So to answer your question, it would depend on your available drive space..

0 Karma

somesoni2
Revered Legend

The license limit is the amount of data that you can index daily. The retention period is how long you want your indexed data to be available in Splunk (for search) and affected by the storage capacity on the Indexers. So, find out how much disk storage you've on your indexes and set the retention period accordingly. This will help http://docs.splunk.com/Documentation/Splunk/6.4.3/Capacity/HowSplunkcalculatesdiskstorage

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...