I can see the retention policy of the indexes in /opt/splunk/etc/master-apps/_cluster/local/indexes.conf
in frozenTimePeriodInSecs
. I wonder where I can see in Splunk Web? We need a nice screenshot of that for auditing ...
I am pretty sure it is not visible in any ui, but you can run a search to get the value and format it accordingly.
Here is the search:
| rest /services/data/indexes | fields title froz* | rename title as index
I am pretty sure it is not visible in any ui, but you can run a search to get the value and format it accordingly.
Here is the search:
| rest /services/data/indexes | fields title froz* | rename title as index
I noticed that some of the indexes (such as _fishbucket) were in the list more than once, so I used deadup to drop the dupes. I also tossed in days and a row number:
| rest /services/data/indexes
| rename title as index | dedup index | sort index
| streamstats count as Row
| eval Days=frozenTimePeriodInSecs/86400
| fields Row index frozenTimePeriodInSecs Days
Gorgeous - thank you both.