<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to change parameters of index which contains data in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-change-parameters-of-index-which-contains-data/m-p/151277#M5672</link>
    <description>&lt;P&gt;I was so far from what Konstantinow asked. I think that is the correct answer.&lt;BR /&gt;
Thanks again.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Apr 2015 13:47:38 GMT</pubDate>
    <dc:creator>stephanefotso</dc:creator>
    <dc:date>2015-04-20T13:47:38Z</dc:date>
    <item>
      <title>How to change parameters of index which contains data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-change-parameters-of-index-which-contains-data/m-p/151275#M5670</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;
I have index in cluster which has data. And i need to change frozenTimePeriodInSecs and maxTotalDataSizeMB parameters. Can i manually edit it in %Splunk%\etc\master-apps_cluster\local\indexes.conf or i need to do it by another way?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 12:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-change-parameters-of-index-which-contains-data/m-p/151275#M5670</guid>
      <dc:creator>Konstantinov</dc:creator>
      <dc:date>2015-04-20T12:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to change parameters of index which contains data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-change-parameters-of-index-which-contains-data/m-p/151276#M5671</link>
      <description>&lt;P&gt;Yes, in your case the first step is to edit the file in &lt;CODE&gt;$SPLUNK_HOME/etc/master-apps/_cluster/local/indexes.conf&lt;/CODE&gt; manually on the cluster master. Then you need to roll out the configuration bundle to the indexer peers either through the web ui or the CLI on the master node as described: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Updatepeerconfigurations"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Updatepeerconfigurations&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Double and triple check those settings are correct before pushing the configuration out since as soon as each peer updates it'll start freezing/deleting data that now qualifies with your new settings if they're accidentally too small.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 13:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-change-parameters-of-index-which-contains-data/m-p/151276#M5671</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2015-04-20T13:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to change parameters of index which contains data</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-change-parameters-of-index-which-contains-data/m-p/151277#M5672</link>
      <description>&lt;P&gt;I was so far from what Konstantinow asked. I think that is the correct answer.&lt;BR /&gt;
Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 13:47:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-change-parameters-of-index-which-contains-data/m-p/151277#M5672</guid>
      <dc:creator>stephanefotso</dc:creator>
      <dc:date>2015-04-20T13:47:38Z</dc:date>
    </item>
  </channel>
</rss>

