Splunk Cloud Platform

Splunk Cloud DDAA

splunkcol
Builder

Sorry for the bad translation.

I have a Cloud client.

The license is 50GB by day

Additional DDAA has been contracted about what is not very clear to me, the shared documentation seems to be outdated or not available.

https://docs.splunk.com/Documentation/SplunkCloud/8.0.2007/User/DataArchiver

https://docs.splunk.com/Documentation/SplunkCloud/8.0.2007/Service/SplunkCloudservice#Storage

https://docs.splunk.com/Documentation/SplunkCloud/8.0.2007/Service/SplunkCloudservice#Search

splunkcol_0-1651792160557.png

When I go to "Settings" - "Indexes" I can see the indexes used by this client and the others that are internal to splunk from what I see.

 

I see that one of the indexes has already reached the maximum size of 500GB and I don't know if it has the DDAA active.

splunkcol_1-1651792240438.png

According to this image I understand that the DDAA is active? I must do something?

I am worried if information is being lost since the client needs to retain that data for a long time

splunkcol_2-1651792407010.png

 

 

Labels (2)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Once DDAA is activated for an index, there is nothing more you need to do.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

@splunkcol There have been OOB conversations lately about some confusion over the DDAA period.  It's common (and reasonable) to think the Searchable Retention and the Archive Retention are separate measurements, but that is not the case.  As the text under Archive Retention says, the number includes the time the data spent as Searchable.  IOW, the settings shown will result in the data being frozen after 365 days and not archived.  To archive data for 365 days after it's been searchable for 365 days, set DDAA to 730.

---
If this reply helps you, Karma would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

Once DDAA is activated for an index, there is nothing more you need to do.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...