<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: index setting in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534622#M4601</link>
    <description>&lt;P&gt;Yes, both are correct&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226300"&gt;@dall&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;Also keep in mind if you restart the indexer hot buckets will roll to warm. So you may have some buckets that have less than 10 GB. But this will not change frozen process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 03 Jan 2021 05:49:19 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-01-03T05:49:19Z</dc:date>
    <item>
      <title>index setting</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534443#M4577</link>
      <description>&lt;P&gt;hi In my index i have added this things&lt;/P&gt;&lt;P&gt;&amp;nbsp;[ind1]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;homePath=&lt;/STRONG&gt; $SPLUNK_DB/ind1/db&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;coldPath=&lt;/STRONG&gt; $SPLUNK_DB/ind1/colddb&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;thawedPath=&lt;/STRONG&gt; $SPLUNK_DB/ind1/thaweddb&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;maxHotBuckets=10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;maxDataSize&lt;/STRONG&gt;=10000&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;maxWarmDBCount&lt;/STRONG&gt;=300&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;maxTotalDataSizeMB=200000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;frozenTimePeriodInSecs&lt;/STRONG&gt;=31536000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;coldToFrozenDir&lt;/STRONG&gt;=$SPLUNK_DB/ ind1/frozendb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that means after 1 year data will be deleted ??&lt;/P&gt;&lt;P&gt;if i ll not add volume for this it ll affect my index or what???&lt;/P&gt;&lt;P&gt;please help on this&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 07:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534443#M4577</guid>
      <dc:creator>dall</dc:creator>
      <dc:date>2020-12-30T07:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: index setting</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534450#M4578</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226300"&gt;@dall&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Since you defined&amp;nbsp;&lt;STRONG&gt;coldToFrozenDir&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;old data will not be deleted but move to&amp;nbsp;&lt;STRONG&gt;coldToFrozenDir&amp;nbsp;&lt;/STRONG&gt;path.&lt;/P&gt;&lt;P&gt;Retention mechanism works according to two parameters.&amp;nbsp;&lt;STRONG&gt;maxTotalDataSizeMB&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;frozenTimePeriodInSecs&amp;nbsp;&lt;/STRONG&gt;. Whichever hits first indexer will move oldest raw data to&amp;nbsp;&lt;STRONG&gt;coldToFrozenDir&amp;nbsp;&lt;/STRONG&gt;path. It means if your index size goes over 200 GB before 1 year, raw data will be moved to&amp;nbsp;&lt;STRONG&gt;coldToFrozenDir.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You should better change&amp;nbsp;&lt;STRONG&gt;coldToFrozenDir&amp;nbsp;&lt;/STRONG&gt;to another disk or NFS path, because you will not free space.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2020 08:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534450#M4578</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-30T08:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: index setting</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534539#M4590</link>
      <description>&lt;P&gt;if we ll not set coldtofrozendir data ll not move to that path and that ll deleted directly ??&lt;/P&gt;&lt;P&gt;or if ll mention that path that means that ll create a folder externally ??&lt;/P&gt;</description>
      <pubDate>Thu, 31 Dec 2020 05:54:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534539#M4590</guid>
      <dc:creator>dall</dc:creator>
      <dc:date>2020-12-31T05:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: index setting</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534622#M4601</link>
      <description>&lt;P&gt;Yes, both are correct&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226300"&gt;@dall&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;Also keep in mind if you restart the indexer hot buckets will roll to warm. So you may have some buckets that have less than 10 GB. But this will not change frozen process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jan 2021 05:49:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/index-setting/m-p/534622#M4601</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-03T05:49:19Z</dc:date>
    </item>
  </channel>
</rss>

