Installation

How should I set my retention policy based on my daily license size?

mprreddy51
Explorer

Hi Experts,

I have a question regarding license and retention policy.

For example, I have a license of 1GB/day and my server is generating logs approximately 5MB/day. How many days can I set my retention policy on this?

Thanks

-P

Labels (1)
0 Karma
1 Solution

somesoni2
Revered Legend

The license limit is the amount of data that you can index daily. The retention period is how long you want your indexed data to be available in Splunk (for search) and affected by the storage capacity on the Indexers. So, find out how much disk storage you've on your indexes and set the retention period accordingly. This will help http://docs.splunk.com/Documentation/Splunk/6.4.3/Capacity/HowSplunkcalculatesdiskstorage

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Licensing and retention are like comparing apples to oranges.. Licensing is constrained by how much data you index per day while retention is constrained by how big your storage is. So if you had a 1TB drive and only indexed 1GB/day (Using 1 index as an example) then you could set up each bucket to retain 200GB before rolling it to the next bucket which is a bit overkill. Now if you had a 2GB drive then you would want to decrease the size of each bucket to prevent the drive from filling up.. Unless you specify a frozen bucket archive, it will be deleted so you can keep indexing new data.

So to answer your question, it would depend on your available drive space..

0 Karma

somesoni2
Revered Legend

The license limit is the amount of data that you can index daily. The retention period is how long you want your indexed data to be available in Splunk (for search) and affected by the storage capacity on the Indexers. So, find out how much disk storage you've on your indexes and set the retention period accordingly. This will help http://docs.splunk.com/Documentation/Splunk/6.4.3/Capacity/HowSplunkcalculatesdiskstorage

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...