<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: differences between warm and cold buckets? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/differences-between-warm-and-cold-buckets/m-p/104389#M3872</link>
    <description>&lt;P&gt;Accepting this answer, since it more or less answered what I asked. Though, technically the only real difference seems to be location. Splunk rolls warm-to-cold based on age, but there's nothing in the structure of the buckets that would prevent manually moving one to the other, for instance. The real benefit of warm-to-cold would be in the ability to use less-expensive / slower storage for cold buckets which, in theory, would need to be accessed less often.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Apr 2012 14:54:25 GMT</pubDate>
    <dc:creator>jeff</dc:creator>
    <dc:date>2012-04-09T14:54:25Z</dc:date>
    <item>
      <title>differences between warm and cold buckets?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/differences-between-warm-and-cold-buckets/m-p/104387#M3870</link>
      <description>&lt;P&gt;In Splunk 4.3 (if it matters), besides it's location, is there any difference between a warm and a cold index bucket? Either in its structure or in how Splunk accesses/searches/processes them?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2012 14:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/differences-between-warm-and-cold-buckets/m-p/104387#M3870</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2012-03-29T14:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: differences between warm and cold buckets?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/differences-between-warm-and-cold-buckets/m-p/104388#M3871</link>
      <description>&lt;P&gt;Both warm and cold buckets are searchable; the differences are location and age. You configure the thresholds in &lt;CODE&gt;indexes.conf&lt;/CODE&gt;. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/HowSplunkstoresindexes"&gt;How Splunk stores indexes&lt;/A&gt; and &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Backupindexeddata"&gt;Back up indexed data&lt;/A&gt; in the documentation for more information.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2012 15:12:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/differences-between-warm-and-cold-buckets/m-p/104388#M3871</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2012-03-29T15:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: differences between warm and cold buckets?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/differences-between-warm-and-cold-buckets/m-p/104389#M3872</link>
      <description>&lt;P&gt;Accepting this answer, since it more or less answered what I asked. Though, technically the only real difference seems to be location. Splunk rolls warm-to-cold based on age, but there's nothing in the structure of the buckets that would prevent manually moving one to the other, for instance. The real benefit of warm-to-cold would be in the ability to use less-expensive / slower storage for cold buckets which, in theory, would need to be accessed less often.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Apr 2012 14:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/differences-between-warm-and-cold-buckets/m-p/104389#M3872</guid>
      <dc:creator>jeff</dc:creator>
      <dc:date>2012-04-09T14:54:25Z</dc:date>
    </item>
  </channel>
</rss>

