my understanding is splunk will purge old data in an index when the disk limit is reached.
what is the easy/fast way to find out the earliest available event in an index?
Thanks in advance
↧