<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shrink or reduce indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Shrink-or-reduce-indexer/m-p/109521#M23035</link>
    <description>&lt;P&gt;And it might be worth to mention that since both of these settings have a default value, the discarding of data will be triggered by whichever of these limits gets hit first. &lt;/P&gt;

&lt;P&gt;So if you want to use time as a limiting factor, ensure that you set the &lt;CODE&gt;maxTotalDataSizeMB&lt;/CODE&gt; so high that you can be certain that &lt;CODE&gt;frozenTimePeriodInSecs&lt;/CODE&gt; will trigger before the size constraint. And vice versa.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2014 19:46:17 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2014-11-10T19:46:17Z</dc:date>
    <item>
      <title>Shrink or reduce indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Shrink-or-reduce-indexer/m-p/109519#M23033</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;I have been gathering data on an indexer for more than 2 years and though data has been useful but i think we can reduce the data to 1.5 yrs, is there is a way to shrink truncate indexers?&lt;/P&gt;

&lt;P&gt;What are recommended ways to maintain life of data, i know ageing from hot to warl to cold buckets is something i have heard of not sure how it works (does splunk automatically take care of it or is something i need to do as admin?)&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 02:02:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Shrink-or-reduce-indexer/m-p/109519#M23033</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-11-10T02:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Shrink or reduce indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Shrink-or-reduce-indexer/m-p/109520#M23034</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;there are two ways to control the size of your indexes: size and time.&lt;/P&gt;

&lt;P&gt;When you create or configer an index, you can give the index a maximum size (maxTotalDataSizeMB). Whenever this size is reached, events are frozen. This can be done via WebUI. The second option is to configure a time period, whenever all events are older than the time period, the events are frozen (frozenTimePeriodInSecs). If you have no action defined for the transition to frozen (for example a script) the events are deleted. You can find additional infos here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf"&gt;link&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;Greetings&lt;/P&gt;

&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 09:13:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Shrink-or-reduce-indexer/m-p/109520#M23034</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2014-11-10T09:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Shrink or reduce indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Shrink-or-reduce-indexer/m-p/109521#M23035</link>
      <description>&lt;P&gt;And it might be worth to mention that since both of these settings have a default value, the discarding of data will be triggered by whichever of these limits gets hit first. &lt;/P&gt;

&lt;P&gt;So if you want to use time as a limiting factor, ensure that you set the &lt;CODE&gt;maxTotalDataSizeMB&lt;/CODE&gt; so high that you can be certain that &lt;CODE&gt;frozenTimePeriodInSecs&lt;/CODE&gt; will trigger before the size constraint. And vice versa.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 19:46:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Shrink-or-reduce-indexer/m-p/109521#M23035</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2014-11-10T19:46:17Z</dc:date>
    </item>
  </channel>
</rss>

