Answer Posted / Ayush Srivastava
Data aging in Splunk is managed through index rotation. Each index has a retention policy, defining how long data will be kept before it's rotated or archived. Once an index reaches its retention limit, old events are removed to make space for new ones. Data can also be purged manually if needed.
| Is This Answer Correct ? | 0 Yes | 0 No |
Post New Answer View All Answers