How to config graylog data save days

Hello All, I’ve a question about the graylog settings. I need to save 30 days old data for our system. Anyone knows how to config this? Thanks


Submit an answer
You can type!ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

If you only want to retain log data for 30 days, you can set Graylog’s retention strategy in its configuration file:

elasticsearch_max_time_per_index = 1d
elasticsearch_max_number_of_indices = 30
retention_strategy = delete

This configures Elasticsearch to have one index per day with a total of 30 indexes meaning only 30 days worth of data will be stored. You may see better search performance if you adjust the values (e.g. 12 hours and 60 indices).