The FrozenFreeUp app allows you to remove the archived frozen data from Splunk indexer instance. The app deletes the db_ and rb_ folders with specified age according to the configurations in the inputs.conf and frozen.conf files. This app should be installed on the Indexer servers. Currently this app supports Indexers installed on nix servers. Important Note: Always consider organization’s data retention policies while setting up the configurations. Make sure to give the exact Frozen path configured in Splunk. Wrong path may lead to the removal of unintended data. **************************************************************************** Contributors: Dr.Simily Joseph - Computer Science Professor Subin Nidiyandiyil - Cyber Security Technical Consultant ****************************************************************************
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources