<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How limit my index growth in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200969#M39714</link>
    <description>&lt;P&gt;Hi Splunk Users,&lt;/P&gt;

&lt;P&gt;I am having an issue with my indexes growing very large and clogging up the space on my disk.&lt;/P&gt;

&lt;P&gt;For example: I have noticed the index 'perfmon' getting very large so I went ahead and set the limit to 5 GB. I was reading once the limit is reached it would clean up automically and delete older data. However I see in Fire Brigade that the index size is still 25 GB. How can that be if I limited to be 5 GB?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;

&lt;P&gt;Oliver&lt;/P&gt;</description>
    <pubDate>Tue, 27 Oct 2015 12:11:00 GMT</pubDate>
    <dc:creator>omuelle1</dc:creator>
    <dc:date>2015-10-27T12:11:00Z</dc:date>
    <item>
      <title>How limit my index growth</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200969#M39714</link>
      <description>&lt;P&gt;Hi Splunk Users,&lt;/P&gt;

&lt;P&gt;I am having an issue with my indexes growing very large and clogging up the space on my disk.&lt;/P&gt;

&lt;P&gt;For example: I have noticed the index 'perfmon' getting very large so I went ahead and set the limit to 5 GB. I was reading once the limit is reached it would clean up automically and delete older data. However I see in Fire Brigade that the index size is still 25 GB. How can that be if I limited to be 5 GB?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;

&lt;P&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 12:11:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200969#M39714</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2015-10-27T12:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: How limit my index growth</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200970#M39715</link>
      <description>&lt;P&gt;Hi omuelle1, to clarify, I am assuming that you set "maxTotalDataSizeMB" for the index to 5000. If that is the case, some possible explanations:&lt;/P&gt;

&lt;P&gt;-Splunk hasn't been restarted and needs to be in order for the change to take effect&lt;BR /&gt;
-There is something in the way as far as file permissions go, and splunk can't delete the buckets. Check splunkd.log&lt;BR /&gt;
-Fire Brigade (haven't worked with that) is reporting false information, or old information. do a " du -sh /path/to/index " to find out the current size&lt;/P&gt;

&lt;P&gt;Let me know if any of this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 12:37:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200970#M39715</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2015-10-27T12:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: How limit my index growth</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200971#M39716</link>
      <description>&lt;P&gt;Thank you for the fast answer.&lt;/P&gt;

&lt;P&gt;Yes you are right, that's the setting I used.&lt;BR /&gt;
 - I did restart Splunk&lt;BR /&gt;
 - Permissions are fine&lt;BR /&gt;
 - I did check the actual sizes in the folders and it matches what I see in FB&lt;/P&gt;

&lt;P&gt;I went ahead and set the retention policy to 5 days&lt;BR /&gt;
frozenTimePeriodInSecs = 432000&lt;/P&gt;

&lt;P&gt;since I really don't need the data longer than 5 days and it actually cleared up space. I might have to clarify that the the index was already 25 GB when I set it to 5 GB max, however I was expecting that it would automatically clean it up to 5 GB.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 13:01:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200971#M39716</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2015-10-27T13:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: How limit my index growth</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200972#M39717</link>
      <description>&lt;P&gt;Hi omulle1, glad to help! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Yes, there is an interval ( I think 60 seconds by default ) that splunk will examine it's indexes and freeze buckets ( individual folders within an index directory ) based on the configuration in indexes.conf. &lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 13:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-limit-my-index-growth/m-p/200972#M39717</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2015-10-27T13:14:12Z</dc:date>
    </item>
  </channel>
</rss>

