<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling index in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573824#M1164</link>
    <description>&lt;P&gt;In theory, you could set disabled=true in your indexes.conf for any index.&lt;/P&gt;&lt;P&gt;But.&lt;/P&gt;&lt;P&gt;You probably won't get any performance-wise relief since I suppose the events would still get ingested and parsed, only at the end of the pipeline they wouldn't get written into the index.&lt;/P&gt;&lt;P&gt;More importantly, I suppose (but haven't checked it, I must admit) that in case of a disabled index Splunk would react as if the index was not defined at all and - if you have one defined - would place the events in your last-resort index.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Nov 2021 13:33:13 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-11-05T13:33:13Z</dc:date>
    <item>
      <title>Disabling index</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573821#M1163</link>
      <description>&lt;P&gt;Hi, I am using splunk cloud&amp;nbsp; and&amp;nbsp; I need to disable some indexes temporarily. I am using AWS add-on app to ship AWS ALB logs from an S3 bucket. My daily ingestion data is going beyond the license and I would like to diasble these indexes temporarily.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see there is an option to disable an input in the inputs section, but same option is not available for index. Although in the index listing page it shows as enabled in the last column.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would appreciate if someone has any solution for the problem mentioned above. Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Muzeeb&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 13:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573821#M1163</guid>
      <dc:creator>muzeebm</dc:creator>
      <dc:date>2021-11-05T13:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling index</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573824#M1164</link>
      <description>&lt;P&gt;In theory, you could set disabled=true in your indexes.conf for any index.&lt;/P&gt;&lt;P&gt;But.&lt;/P&gt;&lt;P&gt;You probably won't get any performance-wise relief since I suppose the events would still get ingested and parsed, only at the end of the pipeline they wouldn't get written into the index.&lt;/P&gt;&lt;P&gt;More importantly, I suppose (but haven't checked it, I must admit) that in case of a disabled index Splunk would react as if the index was not defined at all and - if you have one defined - would place the events in your last-resort index.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 13:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573824#M1164</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-05T13:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling index</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573834#M1165</link>
      <description>&lt;P&gt;in indexes.conf is this warning&lt;/P&gt;&lt;PRE&gt;disabled = &amp;lt;boolean&amp;gt;
* Toggles your index entry off and on.
* Set to "true" to disable an index.
* CAUTION: Do not set this setting to "true" on remote storage enabled indexes.
* Default: false&lt;/PRE&gt;&lt;P&gt;If I have understood right in splunk cloud they are used smartstore which is remote storage. So you couldn’t set it even you technically could.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 15:08:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573834#M1165</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-05T15:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling index</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573843#M1166</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt; &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new to splunk cloud. How do I access on&amp;nbsp;&lt;SPAN&gt;indexes.conf file in a splunk cloud environment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Muzeeb&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 16:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573843#M1166</guid>
      <dc:creator>muzeebm</dc:creator>
      <dc:date>2021-11-05T16:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling index</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573848#M1167</link>
      <description>&lt;P&gt;If you have enough rights, you could see those under Settings-&amp;gt; &amp;nbsp;Indexes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 19:05:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573848#M1167</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-05T19:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling index</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573897#M1169</link>
      <description>&lt;P&gt;Ahh. I didn't notice we're talking about the cloud service. Simple answer is - you can't. You don't have direct access to configuration files. Some settings you can manipulate by deploying apps with needed settings but for some it's necessary to contact support.&lt;/P&gt;&lt;P&gt;But the question is if spunk cloud uses remote storage as &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt; suggested. I'd strongly suspect that so you probably should disable ingestion of events, not the indexes themselves.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Nov 2021 08:51:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/573897#M1169</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-06T08:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling index</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/574104#M1173</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229079"&gt;@muzeebm&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You cannot access the indexing tier as it will be under the control of splunk support,&lt;/P&gt;&lt;P&gt;For your query to disable the index, you don't have an option via GUI to disable it, you can only edit the retention or delete the index if you are allotted sc_admin access to your cloud stack.&lt;/P&gt;&lt;P&gt;Hope this info helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 00:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Disabling-index/m-p/574104#M1173</guid>
      <dc:creator>Roy_9</dc:creator>
      <dc:date>2021-11-09T00:29:46Z</dc:date>
    </item>
  </channel>
</rss>

