Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

indexes.conf do not working。

$
0
0
hi everyone : i have set indexes.conf link this:> [qt]>coldToFrozenDir = /SplunkBack/splunk/qt>frozenTimePeriodInSecs = 20736000 20736000 = 240 days but i can still search last year's data。 splunk enterprise = 6.6.3 thinks

Viewing all articles
Browse latest Browse all 47296

Trending Articles