Getting Data In

Why is the frozen data not deleted automatically?

knarayana
New Member

I have these settings for my index

maxTotalDataSizeMB = 100000
coldPath = C:/colddb
homePath = C:/db
coldToFrozenDir = C:/frozendb
thawedPath = C:/thaweddb

Data is not deleted as it moves to forzendb.
forzendb is now 128GB.

Not sure why this is not working as expected.

Thanks

0 Karma
1 Solution

HiroshiSatoh
Champion

The forzen data is not deleted automatically. It is outside the management of splunk. If deletion is necessary, it is necessary to delete it using a shell etc.

View solution in original post

datasearchninja
Communicator

If you want to delete when freezing, do not set a coldToFrozenDir, and then data will not be moved to the frozen directory, but be deleted instead

See https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf .

HiroshiSatoh
Champion

The forzen data is not deleted automatically. It is outside the management of splunk. If deletion is necessary, it is necessary to delete it using a shell etc.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...