<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Cloud Index MaxSize Issue in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Splunk-Cloud-Index-MaxSize-Issue/m-p/745766#M3783</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hey everyone,&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a question on Splunk Cloud Index MaxSize.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I am having an issue with Splunk Cloud Index MaxSize. My index max size is set to 500GB, but the current size has reached 530GB, and some latest events (from last week) are not in the index but are going to archive storage.&lt;BR /&gt;We have 3 months of searchable retention and 3 months of archive, and the archive dashboard is showing the latest event from last week.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We have 8 indexers, which are clustered, and two dedicated search heads (not clustered).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;My question is, can I update the index maxsize (to unlimited) on the GUI, and will it replicate to all the indexers and 2 search heads, or should I open a support case for that?&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The second question is, can I restore the logs that went to archiving due to a maxsize issue to a searchable index again?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2025 09:09:06 GMT</pubDate>
    <dc:creator>tech_g706</dc:creator>
    <dc:date>2025-05-08T09:09:06Z</dc:date>
    <item>
      <title>Splunk Cloud Index MaxSize Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Splunk-Cloud-Index-MaxSize-Issue/m-p/745766#M3783</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hey everyone,&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a question on Splunk Cloud Index MaxSize.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I am having an issue with Splunk Cloud Index MaxSize. My index max size is set to 500GB, but the current size has reached 530GB, and some latest events (from last week) are not in the index but are going to archive storage.&lt;BR /&gt;We have 3 months of searchable retention and 3 months of archive, and the archive dashboard is showing the latest event from last week.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We have 8 indexers, which are clustered, and two dedicated search heads (not clustered).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;My question is, can I update the index maxsize (to unlimited) on the GUI, and will it replicate to all the indexers and 2 search heads, or should I open a support case for that?&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The second question is, can I restore the logs that went to archiving due to a maxsize issue to a searchable index again?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 09:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Splunk-Cloud-Index-MaxSize-Issue/m-p/745766#M3783</guid>
      <dc:creator>tech_g706</dc:creator>
      <dc:date>2025-05-08T09:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Index MaxSize Issue</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Splunk-Cloud-Index-MaxSize-Issue/m-p/745767#M3784</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309054"&gt;@tech_g706&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not sure why data from last week would be going to archive, this might be something you need to speak to Splunk support about, however regarding the retrieval of the archive data then if this is in DDAA then you can temporarily restore it but I dont think its possible to keep it restored.&lt;/P&gt;&lt;P&gt;I would speak to Splunk Support - if there has been an issue which has caused the data to archive prematurely then they may be able to have it restored for you, but it isnt something that you'd be able to do yourself.&lt;/P&gt;&lt;P&gt;If you update the Max size via the GUI it will replicate the configuration to the relevant components within the Splunk Cloud stack - you do not need to worry so much about how/where it goes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 09:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Splunk-Cloud-Index-MaxSize-Issue/m-p/745767#M3784</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-08T09:25:20Z</dc:date>
    </item>
  </channel>
</rss>

