splunkd.log gets indexed in _internal index. From this index , i could able to get data for last 1 month. I need to have splunkd.log for Jan2013 . How do i get it ? Was the data moved to Warm db,cold db? If ,so how can i perform Search option against those buckets ?
↧