ExamGecko
Question list
Search
Search

Question 165 - SPLK-1003 discussion

Report
Export

The following stanza is active in indexes.conf:

[cat_facts]

maxHotSpanSecs = 3600

frozenTimePeriodInSecs = 2630000

maxTota1DataSizeMB = 650000

All other related indexes.conf settings are default values.

If the event timestamp was 3739283 seconds ago, will it be searchable?

A.
Yes, only if the bucket is still hot.
Answers
A.
Yes, only if the bucket is still hot.
B.
No, because the index will have exceeded its maximum size.
Answers
B.
No, because the index will have exceeded its maximum size.
C.
Yes, only if the index size is also below 650000 MB.
Answers
C.
Yes, only if the index size is also below 650000 MB.
D.
No, because the event time is greater than the retention time.
Answers
D.
No, because the event time is greater than the retention time.
Suggested answer: D

Explanation:

The correct answer is D. No, because the event time is greater than the retention time.

According to the Splunk documentation1, the frozenTimePeriodInSecs setting in indexes.conf determines how long Splunk software retains indexed data before deleting it or archiving it to a remote storage. The default value is 188697600 seconds, which is equivalent to six years. The setting can be overridden on a per-index basis.

In this case, the cat_facts index has a frozenTimePeriodInSecs setting of 2630000 seconds, which is equivalent to about 30 days. This means that any event that is older than 30 days from the current time will be removed from the index and will not be searchable.

The event timestamp was 3739283 seconds ago, which is equivalent to about 43 days. This means that the event is older than the retention time of the cat_facts index and will not be searchable.

The other settings in the stanza, such as maxHotSpanSecs and maxTota1DataSizeMB, do not affect the retention time of the events. They only affect the size and duration of the buckets that store the events.

asked 23/09/2024
Foo goo
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first