<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/646782#M16573</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194518"&gt;@schose&lt;/a&gt;,&amp;nbsp;apologies, I'm just seeing your reply.&lt;BR /&gt;&lt;BR /&gt;To test for high cardinality, I'm thinking the following would work:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Packing an Index&lt;/STRONG&gt;: Put a bunch of source/sourcetypes all into one index.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Multiplying sources&lt;/STRONG&gt;: If file based, use the filename, or transform the source by appending values.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Multiplying sourcetypes/Packing a Source&lt;/STRONG&gt;: Set the sourcetype by appending values (frequency appropriate) like day and hour.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I'd imagine the above can be done with access to a large syslog server or some programmatic manipulation.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 09:25:48 GMT</pubDate>
    <dc:creator>rkantamaneni</dc:creator>
    <dc:date>2023-06-13T09:25:48Z</dc:date>
    <item>
      <title>index.conf: Can anyone explain to me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/588151#M11774</link>
      <description>&lt;P&gt;can anyone explain me&amp;nbsp;&lt;SPAN&gt;tsidxWritingLevel variables from 1 to 4 ?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;tsidxWritingLevel = [1|2|3|4]&lt;/PRE&gt;
&lt;P&gt;Reference -&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Indexesconf?_ga=2.85851486.671277735.1646626990-1267829109.1638160623&amp;amp;_gl=1*hp9d3s*_ga*MTI2NzgyOTEwOS4xNjM4MTYwNjIz*_gid*NjcxMjc3NzM1LjE2NDY2MjY5OTA" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Indexesconf?_ga=2.85851486.671277735.1646626990-1267829109.1638160623&amp;amp;_gl=1*hp9d3s*_ga*MTI2NzgyOTEwOS4xNjM4MTYwNjIz*_gid*NjcxMjc3NzM1LjE2NDY2MjY5OTA&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 14:20:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/588151#M11774</guid>
      <dc:creator>human96</dc:creator>
      <dc:date>2022-03-16T14:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/588865#M11806</link>
      <description>&lt;P&gt;There is no documentation I know of that documents the difference beyond the spec file (&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;&lt;PRE&gt;tsidxWritingLevel = [1|2|3|4]
* Enables various performance and space-saving improvements for tsidx files.&lt;/PRE&gt;&lt;P&gt;It is set to&amp;nbsp; 1 by default in case you have older Splunk versions in the cluster, I use the highest version available (4).&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 04:05:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/588865#M11806</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2022-03-14T04:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/589063#M11824</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i recently wrote a small blog article regarding this setting:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How tsidxWritingLevel affects storage size and performance -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://www.batchworks.de/tsidx-storage-performance/" target="_blank" rel="noopener"&gt;https://www.batchworks.de/tsidx-storage-performance/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;hope it helps,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 12:06:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/589063#M11824</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2022-03-15T12:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/589249#M11830</link>
      <description>&lt;P&gt;Nice work!&lt;/P&gt;&lt;P&gt;As you have test setup already in place, can you do the same with&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;journalCompression = gzip|lz4|zstd
* The compression algorithm that splunkd should use for the rawdata journal
  file of new index buckets.
* This setting does not have any effect on already created buckets. There is
  no problem searching buckets that are compressed with different algorithms.
* "zstd" is only supported in Splunk Enterprise version 7.2.x and higher. Do
  not enable that compression format if you have an indexer cluster where some
  indexers run an earlier version of Splunk Enterprise.
* Default: gzip&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 08:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/589249#M11830</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-03-16T08:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/589260#M11832</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;that's exactly what i planned for my next article. But i can share the first numbers:&lt;/P&gt;&lt;P&gt;After ingest 800MB raw routeros logs into event indexes the rawdata is:&amp;nbsp;&lt;/P&gt;&lt;P&gt;gzip:&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;74.2MB&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;lz4:&amp;nbsp;136.0MB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;zstd:&amp;nbsp;56.4 MB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'll need some more time for a performance review, but will post updates.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Andreas&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 10:33:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/589260#M11832</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2022-03-16T10:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/644748#M16450</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194518"&gt;@schose&lt;/a&gt;This is a really nice blog on the topic, well done! Any plans to update with Splunk 9.x as a test? From a data perspective, comparing bucket complexity (number of source/sourcetypes) might be interesting too (there was a bug a while back with a corner case where high cardinality data perverted the compression optimizations in level 3, this has long been addressed, especially since it's the default in 9.x). Thanks, will be sharing your blog to explain tsidxWritingLevel to folks.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 13:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/644748#M16450</guid>
      <dc:creator>rkantamaneni</dc:creator>
      <dc:date>2023-05-26T13:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/644751#M16451</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247800"&gt;@rkantamaneni&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Well, i can rerun the tests with a 9.x version, but wouldn't expect different results with the same level setting.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would be also interested in behaviour for different sourcetypes, as we see huge differences there. Do you have an idea for good high cardinality logfiles?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 13:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/644751#M16451</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2023-05-26T13:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/646782#M16573</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194518"&gt;@schose&lt;/a&gt;,&amp;nbsp;apologies, I'm just seeing your reply.&lt;BR /&gt;&lt;BR /&gt;To test for high cardinality, I'm thinking the following would work:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;STRONG&gt;Packing an Index&lt;/STRONG&gt;: Put a bunch of source/sourcetypes all into one index.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Multiplying sources&lt;/STRONG&gt;: If file based, use the filename, or transform the source by appending values.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Multiplying sourcetypes/Packing a Source&lt;/STRONG&gt;: Set the sourcetype by appending values (frequency appropriate) like day and hour.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I'd imagine the above can be done with access to a large syslog server or some programmatic manipulation.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 09:25:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/646782#M16573</guid>
      <dc:creator>rkantamaneni</dc:creator>
      <dc:date>2023-06-13T09:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: index.conf- Can anyone explain me tsidxWritingLevel variables from 1 to 4?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/690314#M19598</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194518"&gt;@schose&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Could you please provide the splunk query that is used to check before and after sizes of bucket.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 09:29:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-conf-Can-anyone-explain-to-me-tsidxWritingLevel-variables/m-p/690314#M19598</guid>
      <dc:creator>Vamsi</dc:creator>
      <dc:date>2024-06-11T09:29:06Z</dc:date>
    </item>
  </channel>
</rss>

