<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk remove data after indexing in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201421#M21801</link>
    <description>&lt;P&gt;this command gives 0 event and null values&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2016 14:37:51 GMT</pubDate>
    <dc:creator>TISKAR</dc:creator>
    <dc:date>2016-09-20T14:37:51Z</dc:date>
    <item>
      <title>splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201413#M21793</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I have a big problem with the addition of data.&lt;BR /&gt;
 initially given 9 million are added. but after I find Splunk removes one million data.&lt;/P&gt;

&lt;P&gt;Can you  help please.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 09:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201413#M21793</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2016-09-20T09:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201414#M21794</link>
      <description>&lt;P&gt;Have you set your search time range to "All Time" ?&lt;/P&gt;

&lt;P&gt;If it doesn't work, then go to Settings -&amp;gt; Indexes -&amp;gt; click on your index &lt;BR /&gt;
 1. Check your index How big is "Current Size" and "Max Size"?&lt;BR /&gt;&lt;BR /&gt;
 2. How many "Event Count" are shown?&lt;BR /&gt;
You might need to add more space if your index is running out of space &lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 10:07:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201414#M21794</guid>
      <dc:creator>haley_swarnapat</dc:creator>
      <dc:date>2016-09-20T10:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201415#M21795</link>
      <description>&lt;P&gt;Thank you for you reaction,&lt;BR /&gt;
range=ALL Time&lt;BR /&gt;
The Max Size=500GB&lt;BR /&gt;
The current Size=1MB (I find it also removes all events)&lt;BR /&gt;
Event Count=0 &lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 10:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201415#M21795</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2016-09-20T10:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201416#M21796</link>
      <description>&lt;P&gt;Splunk is a FIFO system so if your index is set at a size of 80G and 10M events is roughly 1G, then the first (earliest) 10G  will be frozen (purged) to make room for the last (latest) 10G.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 13:12:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201416#M21796</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-09-20T13:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201417#M21797</link>
      <description>&lt;P&gt;Thank you for your reaction, &lt;BR /&gt;
I create author index and , and I created a folder only contains three files, the Splunk began indexing but at some point it removes all that has indexed(COUNT EVENT=0) , knowing that I have not found this problem in Splunk light.&lt;/P&gt;

&lt;P&gt;index characteristic:&lt;BR /&gt;
range=ALL Time&lt;BR /&gt;
The Max Size=500GB&lt;/P&gt;

&lt;P&gt;index.conf:&lt;BR /&gt;
[indexTest]&lt;BR /&gt;
coldPath = $SPLUNK_DB/ffjj/colddb&lt;BR /&gt;
enableDataIntegrityControl = 0&lt;BR /&gt;
enableTsidxReduction = 0&lt;BR /&gt;
homePath = $SPLUNK_DB/indexTest/db&lt;BR /&gt;
maxTotalDataSizeMB = 512000&lt;BR /&gt;
thawedPath = $SPLUNK_DB/indexTest/thaweddb&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;input.conf:&lt;BR /&gt;
[monitor:///data/splunk/test]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = indexTest&lt;BR /&gt;
sourcetype = LICENCIE&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201417#M21797</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2020-09-29T11:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201418#M21798</link>
      <description>&lt;P&gt;You have tagged this &lt;CODE&gt;splunk-enterprise&lt;/CODE&gt; but then you mention "splunk light"  What are you using?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 13:52:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201418#M21798</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-09-20T13:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201419#M21799</link>
      <description>&lt;P&gt;Now I use splubk Entrprise . (before I used splunk light I has not found The Problem)&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 14:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201419#M21799</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2016-09-20T14:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201420#M21800</link>
      <description>&lt;P&gt;What do you see with this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | tstats count valuse(sourcetype) where index=* OR index=_*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 20 Sep 2016 14:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201420#M21800</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-09-20T14:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201421#M21801</link>
      <description>&lt;P&gt;this command gives 0 event and null values&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 14:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201421#M21801</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2016-09-20T14:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201422#M21802</link>
      <description>&lt;P&gt;It's a typo, he was mentioning this:&lt;BR /&gt;
| tstats count values(sourcetype) where index=* OR index=_*&lt;/P&gt;

&lt;P&gt;Just FYI, if your free space falls below 5GB, Splunk will stop indexing by default.&lt;BR /&gt;
If this is the case, you might need to delete some temp files from your OS.&lt;BR /&gt;
Or you can adjust this limit by going to : Settings -&amp;gt; System Settings -&amp;gt; General Settings -&amp;gt; Pause indexing if free disk space (in MB) falls below *&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 04:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201422#M21802</guid>
      <dc:creator>haley_swarnapat</dc:creator>
      <dc:date>2016-09-21T04:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201423#M21803</link>
      <description>&lt;P&gt;after searching , I think the problem comes from three files , I install Splunk entreprise in other computer problems remains with me these three files , I replaced these files by three other files of the same format and size but different data, me the data are added without problem.&lt;/P&gt;

&lt;P&gt;Thank you all&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 13:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201423#M21803</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2016-09-21T13:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk remove data after indexing</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201424#M21804</link>
      <description>&lt;P&gt;Hello every one,&lt;/P&gt;

&lt;P&gt;Thank you for your participation,&lt;BR /&gt;
I found the problem , but I did not understand why the problem is that I have more time , I added from the fields of these dates in TIMESTAMP_FIELDS after I left That a single TIMESTAMP_FIELDS field , I'll find out why . and what is the criteria on TIMESTAMP_FIELDS ??&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-remove-data-after-indexing/m-p/201424#M21804</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2020-09-29T11:06:23Z</dc:date>
    </item>
  </channel>
</rss>

