Configuration files for data policy
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Configuration files for data policy
Splunk's data policy is managed in Splunk through the indexes.conf configuration file. You should make changes to this file in $SPLUNK_HOME/etc/bundles/local or create a new bundle.
Please note: settings in indexes.conf are per index rather than a global server setting.
Before making changes to how Splunk manages data consider:
- Your company's data retention policies.
- How much data your Splunk deployment will consume (For example: daily rate (50GB/day)).
- Where your Splunk index datastores will live.
This documentation applies to the following versions of Splunk: 3.0 , 3.0.1 View the Article History for its revisions.