JBOSS Admin

Friday, May 25, 2012

Splunk - Purge events based on age

Purge event data older than 30 days in a specific index.

Update indexes.conf 

[my-index]
coldPath = $SPLUNK_DB/my-index/colddb
homePath = $SPLUNK_DB/my-index/db
thawedPath = $SPLUNK_DB/my-index/thaweddb
frozenTimePeriodInSecs = 2592000



posted by Jayanthi Krishnamurthy @ 5:43 PM   0 Comments

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home

Newer›  ‹Older

About Me

Name: Jayanthi Krishnamurthy

View my complete profile

Posts

  • Splunk - Purge events based on age

Older Posts Newer Posts

Archives

Subscribe to
Posts [Atom]