I would like to setup the data retention policy only for 10 days for below internaldb logs to avoid the space issues in Splunk.
/opt/splunk/indexer/splunk/var/lib/splunk/_internaldb/db
Can someone tell me where to update the configuration stanza.
Thanks,
Ramu Chittiprolu
You can configure retention policy per index like this:
[_internal]
homePath = $SPLUNK_DB/_internaldb/db
coldPath = $SPLUNK_DB/_internaldb/colddb
thawedPath = $SPLUNK_DB/_internaldb/thaweddb
tstatsHomePath = volume:_splunk_summaries/_internaldb/datamodel_summary
maxDataSize = 1000
maxHotSpanSecs = 432000
frozenTimePeriodInSecs = 864000
You can configure retention policy per index like this:
[_internal]
homePath = $SPLUNK_DB/_internaldb/db
coldPath = $SPLUNK_DB/_internaldb/colddb
thawedPath = $SPLUNK_DB/_internaldb/thaweddb
tstatsHomePath = volume:_splunk_summaries/_internaldb/datamodel_summary
maxDataSize = 1000
maxHotSpanSecs = 432000
frozenTimePeriodInSecs = 864000