Changing technology landscapes and accelerated enterprise digital transformation have produced enormous amounts of data that needs a good retention policy to enable business agility, growth and improved customer experience.
Splunk Cloud Platform provides customers flexibility and choice on how their data is managed offering the following storage types in 500 GB blocks to address the needs of a diverse set of use cases and retention schemes:
DDAS provides readily searchable data storage in Splunk Cloud Platform and is the primary entry point for newly ingested data. DDSS provides a path for customers to self-manage data archival and restoration functions should the need arise to search against it. With DDAA Splunk will manage archival and restoration functions for customers.
There are two key differences between the two capabilities:
Dynamic Data Active Archive and Dynamic Data Self-Storage are built on the same design principles:
Now let’s look under the hood and learn more about how DDAA works: Dynamic Data Active Archive is an optional service. Once subscribed to the service, customers will notice a few changes to their index listing page.
Storage Type now has a new value, Splunk Archive. For indexes that roll over into the archive, a new Restore option is available; more on that later.
For an index, customers can now choose Splunk Archive or Self-Storage. Note that these options are mutually exclusive, i.e. for an index you can either chose Archive or Self-Storage, NOT both.
If customers select the Splunk Archive option they can specify the Retention Period for that archive. The Retention Period is based on the entitlement selected when the customer subscribed to the service.
Once the options are set, such as the Size, or the Searchable time criteria is met, the data is rolled into Splunk Archive. As mentioned earlier, only when the data is successfully moved to the archive is it then deleted from Splunk Cloud Platform. That's it!
Keep in mind that the day may arrive when a customer will be asked to restore data from the archive for an incident investigation or to meet a compliance request. With 4 simple clicks customers can easily restore the data from the archive into their Splunk Cloud Platform instance.
Customers need only to specify the time slice, select a description, check the size and they’re all set! If the customer wants to notify others once the data restore is complete, they can specify their email ids. The history of restore requests for that index is available to see details like status, data volume restored, etc.
A couple of key points about data restore:
Once the data is restored into a Splunk cloud instance, it can be searched like any other event data!
If you would like to learn more about DDAA and DDSS please check out our detailed documentation on Splunk Cloud Platform storage.
At Splunk we value customer feedback and continually look to deliver innovations that meet and exceed our customers’ expectations. Dynamic Data Self Storage and Dynamic Data Active Archive are examples of successful collaboration with our customers!
Note: This blog was originally published on October 11, 2018 and has been updated from its previous version.
The world’s leading organizations rely on Splunk, a Cisco company, to continuously strengthen digital resilience with our unified security and observability platform, powered by industry-leading AI.
Our customers trust Splunk’s award-winning security and observability solutions to secure and improve the reliability of their complex digital environments, at any scale.