Retention management without the effort
Data in Splunk ages with time and organizations should decide for themselves how to deal with it. Old data is either deleted automatically or archived in the Splunk instance. Although the archive is created by Splunk, there are no alerts, nor can an automatic removal be scheduled.
A challenge for the organization is to manage these archives, and their expiration dates manually. After archiving, data remains invisible and explicit attention is required to follow up. Old, archived information burdens the organization’s systems and infrastructure, creating a risk of regulatory infringement (for example, GDPR).
To deal with this challenge, we’ve created an application that automates the process of removing old archives, mitigating the effort, and saving time.
Automatic removal of old archived data and complete reporting
ThrowAway is a free add-on for Splunk by BRIGHT. It reviews the archived data and checks backup’s expiration date – if the date is beyond what the client has set, the add-on will remove it.
Moreover, for each event, the system will create a summary report, so the stakeholders could track the events and have full visibility of the activities.
The reports include detailed information about the archive, the date of deletion, what data is available inside, for which indexes, and more.
Documents and resources
ThrowAway Add-on Technical Guide