Set up Splunk to archive your data automatically as it ages. To do this, configure indexes.conf to call archiving scripts located in $SPLUNK_HOME/bin. Edit this file in $SPLUNK_HOME/etc/system/local/, or in your own custom application directory in $SPLUNK_HOME/etc/apps/. For more information on configuration files in general, see how configuration files work. Do not edit the copy in default.
Note: By default, Splunk deletes ALL frozen data. To avoid losing your data, you must specify a valid coldToFrozenScript in $SPLUNK_HOME/etc/system/local/indexes.conf (or your own custom app directory in $SPLUNK_HOME/etc/apps/).
Use Splunk's index aging policy to archiveSplunk rotates old data out of the index based on your data retirement policy. Data moves through several stages, which correspond to file directory locations. Data starts out in the hot database $SPLUNK_HOME/var/lib/splunk/defaultdb/db/db_hot. Then, data moves through the warm database $SPLUNK_HOME/var/lib/splunk/defaultdb/db. Eventually, data is aged into the cold database $SPLUNK_HOME/var/lib/splunk/defaultdb/colddb.
Finally, data reaches the frozen state. Splunk erases frozen index data once it is older than frozenTimePeriodinSecs in indexes.conf. The coldToFrozenScript (also specified in indexes.conf) runs just before the frozen data is erased. The default script simply writes the name of the directory being retired, e.g. /opt/splunk/var/lib/splunk/defaultdb/colddb, to the log file $SPLUNK_HOME/var/log/splunk/splunkd_stdout.log.
Add the following to $SPLUNK_HOME/etc/system/local/indexes.conf:
[<index>] coldToFrozenScript = <script>
Comments
update: windows scripts are now available.
Posted by emma on Sep 22 2008, 12:11pm
@djz:
yes these scripts are not currently available on Windows. they should be available in the next maintenance release. currently, this is being tracked as issue SPL-15940, so check for that in the release notes.
Posted by emma on Sep 12 2008, 5:30pm
This page says that Splunk ships with two archiving scripts, but I couldn't find the referenced scripts in the $SPLUNK_HOME/bin directory. Installed on Windows, so maybe that is the difference?
Posted by djz on Aug 12 2008, 11:40am