hi everyone :
i have set indexes.conf link this:> [qt]>coldToFrozenDir = /SplunkBack/splunk/qt>frozenTimePeriodInSecs = 20736000
20736000 = 240 days
but i can still search last year's data。
splunk enterprise = 6.6.3
thinks
↧