<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why would my audit index grow to over 300g suddenly? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-would-my-audit-index-grow-to-over-300g-suddenly/m-p/376805#M13842</link>
    <description>&lt;P&gt;Unless there is a misconfigured input feeding the audit index, the easiest answer is that there seem to be a large amount of changes in your environment.  The DIY solution would be to search the audit index to identify what changes are occurring.  These could be a script making changes to the Splunk files on disk, or a large/excess amount of activity.  Here's a list of all of the activities that would cause an entry in the audit index: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.1/Security/AuditSplunkactivity"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.1/Security/AuditSplunkactivity&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jun 2018 17:40:00 GMT</pubDate>
    <dc:creator>jowenssi</dc:creator>
    <dc:date>2018-06-07T17:40:00Z</dc:date>
    <item>
      <title>Why would my audit index grow to over 300g suddenly?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-would-my-audit-index-grow-to-over-300g-suddenly/m-p/376803#M13840</link>
      <description>&lt;P&gt;Why would my audit index grow to over 300g suddenly?&lt;BR /&gt;
This happened on the SH. The _audit index normally sits at about 80 mb. So to get an alert that I was nearly out of storage for Splunkhome was a surprise.&lt;BR /&gt;
For immediate impact I altered the size of the index to 500m, let the storage clearup, and reset the storage to allow up to 10g.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 17:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-would-my-audit-index-grow-to-over-300g-suddenly/m-p/376803#M13840</guid>
      <dc:creator>MikeBertelsen</dc:creator>
      <dc:date>2018-06-07T17:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why would my audit index grow to over 300g suddenly?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-would-my-audit-index-grow-to-over-300g-suddenly/m-p/376804#M13841</link>
      <description>&lt;P&gt;Well, with the data already gone, it might be difficult to determine the cause.&lt;BR /&gt;
However - if it still grows fast now, you could simply take a look at what kind of messages appear very frequently, e.g. using the Pattern tab.&lt;BR /&gt;
This would most likely give you an idea why this has happened.&lt;BR /&gt;
Also - is this a personal instance, or a corporate one? Production, dev or test? Available from the internet, or LAN only?&lt;/P&gt;

&lt;P&gt;Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 17:39:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-would-my-audit-index-grow-to-over-300g-suddenly/m-p/376804#M13841</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-06-07T17:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: Why would my audit index grow to over 300g suddenly?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-would-my-audit-index-grow-to-over-300g-suddenly/m-p/376805#M13842</link>
      <description>&lt;P&gt;Unless there is a misconfigured input feeding the audit index, the easiest answer is that there seem to be a large amount of changes in your environment.  The DIY solution would be to search the audit index to identify what changes are occurring.  These could be a script making changes to the Splunk files on disk, or a large/excess amount of activity.  Here's a list of all of the activities that would cause an entry in the audit index: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.1/Security/AuditSplunkactivity"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.1/Security/AuditSplunkactivity&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jun 2018 17:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-would-my-audit-index-grow-to-over-300g-suddenly/m-p/376805#M13842</guid>
      <dc:creator>jowenssi</dc:creator>
      <dc:date>2018-06-07T17:40:00Z</dc:date>
    </item>
  </channel>
</rss>

