Skip to main content


Splunk Data Retention Policy

Updated: November 2021

Type of data Retention timeframe*
License Usage Data - Splunk 5 years
Usage Data - Splunk 5 years
Usage Data - Splunk On-Call**
2 years
Usage Data - Splunk Observability*** 13 months
Support Usage Data - Splunk 5 year
Mobile Device Data 5 years
Support diagnostic files provided by Customers (Splunk On-prem Only) Up to 180 days
*Cloud log and event stream data excluded.
** Formerly VictorOps.
***Formerly SignalFx.