Glass is a Splunk-native archive and restore solution that helps organizations meet long-term data retention requirements for threat hunting and compliance while also improving Splunk performance. Delivered as a Splunk App, Glass integrates directly with Splunk’s indexing policies and archives data to any S3-compatible object store, including S3 Glacier.
Key Benefits:
Security: Enables threat hunting on historical log data, months or even years old, to uncover long-running or previously unnoticed malicious activity.
Compliance: Supports retention requirements for regulatory or internal policies without overburdening your Splunk infrastructure.
Performance: Improves overall Splunk performance by reducing index size through efficient log and metadata archiving.
Flexible Architecture: Built to support additional SIEM and storage platforms beyond Splunk