<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk going down in events indexed in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-going-down-in-events-indexed/m-p/23912#M3758</link>
    <description>&lt;P&gt;All day, I've been watching the amount of events indexed in Splunk go up and down.  It stays in the 1.8-1.9 billion events range, but it's going up and down.  Saw it at 1.96 billion today, and then it went down to 1.93 back to 1.96 and now 1.89.  Is there a default setting somewhere I need to look at?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Apr 2012 23:52:17 GMT</pubDate>
    <dc:creator>nkitmitto</dc:creator>
    <dc:date>2012-04-10T23:52:17Z</dc:date>
    <item>
      <title>Splunk going down in events indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-going-down-in-events-indexed/m-p/23912#M3758</link>
      <description>&lt;P&gt;All day, I've been watching the amount of events indexed in Splunk go up and down.  It stays in the 1.8-1.9 billion events range, but it's going up and down.  Saw it at 1.96 billion today, and then it went down to 1.93 back to 1.96 and now 1.89.  Is there a default setting somewhere I need to look at?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Apr 2012 23:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-going-down-in-events-indexed/m-p/23912#M3758</guid>
      <dc:creator>nkitmitto</dc:creator>
      <dc:date>2012-04-10T23:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk going down in events indexed</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-going-down-in-events-indexed/m-p/23913#M3759</link>
      <description>&lt;P&gt;Check out settings in &lt;CODE&gt;indexes.conf&lt;/CODE&gt;.  As buckets roll from cold to frozen, they will be removed from the index and the indexed event count will go down by the number of events in the bucket.&lt;/P&gt;

&lt;P&gt;Good docs reference @ &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.2.3/Admin/Setaretirementandarchivingpolicy"&gt;http://docs.splunk.com/Documentation/Splunk/4.2.3/Admin/Setaretirementandarchivingpolicy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2012 03:44:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-going-down-in-events-indexed/m-p/23913#M3759</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2012-04-11T03:44:45Z</dc:date>
    </item>
  </channel>
</rss>

