All Apps and Add-ons

Change an existing index frozenTimePeriodInSecs Thru REST

dcroteau
Splunk Employee
Splunk Employee

I know you can create a new index through REST:

curl -k -u admin:changeme https://127.0.0.1:8089/servicesNS/admin/search/data/indexes -d name=mynewindex -d frozenTimePeriodInSecs=#######

Is there a way to change or update an existing indexes frozenTimePeriodInSecs though REST?

0 Karma

supabuck
Path Finder

Hi dcroteau,

Let me know if the suggestion below worked.

Thanks!

-supabuck

0 Karma

supabuck
Path Finder

Hello dcroteau,

This absolutely can be done.

Based upon your example here is what you would do for the case of your index named mynewindex wanted to be changed to a year of retention:

curl -k -u admin:changeme https://127.0.0.1:8089/servicesNS/admin/search/data/indexes/mynewindex -d frozenTimePeriodInSecs=31536000

Specifying it in the path will alter the settings on that index via the REST endpoint.

Regards,
supabuck

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...