<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data going directly to frozen in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-directly-to-frozen/m-p/530186#M89265</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a new index - it's a monster - eating up my disk space. Until I move it to the physical server I need to fix it.&lt;/P&gt;&lt;P&gt;Well, I limited maxTotalDataSizeMB, seem working but the cold storage skipped landed in frozen directly, so I cannot search it.&lt;/P&gt;&lt;P&gt;The hot/warm storage is "local" on VM, the cold, frozen, thawed is an S3.&lt;/P&gt;&lt;P&gt;The optimal idea is 7 days in hot/warm (if over maxTotalDataSizeMB then faster) then go cold for 90 days (no size limit) then thawed for 1 year (no size limit).&lt;/P&gt;&lt;P&gt;here is my current setting&lt;/P&gt;&lt;P&gt;archiver.enableDataArchive = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf archiver.maxDataArchiveRetentionPeriod = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf assureUTF8 = false&lt;BR /&gt;bucketRebuildMemoryHint = 0&lt;BR /&gt;coldPath = /mnt/archive_s3/SPLUNK_DB/indexname/colddb&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf coldPath.maxDataSizeMB = 0&lt;BR /&gt;coldToFrozenDir = /mnt/archive_s3/SPLUNK_DB/indexname/Frozenarchive&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf coldToFrozenScript =&lt;BR /&gt;compressRawdata = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf datatype = event&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf defaultDatabase = main&lt;BR /&gt;enableDataIntegrityControl = 0&lt;BR /&gt;enableOnlineBucketRepair = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf enableRealtimeSearch = true&lt;BR /&gt;enableTsidxReduction = 0&lt;BR /&gt;frozenTimePeriodInSecs = 3024000&lt;BR /&gt;homePath = $SPLUNK_DB/indexname/db&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf homePath.maxDataSizeMB = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketTimeRefreshInterval = 10&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf indexThreads = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf journalCompression = gzip&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxBloomBackfillBucketAge = 30d&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxBucketSizeCacheEntries = 0&lt;BR /&gt;maxConcurrentOptimizes = 6&lt;BR /&gt;maxDataSize = auto_high_volume&lt;BR /&gt;maxGlobalDataSizeMB = 0&lt;BR /&gt;maxHotBuckets = 10&lt;BR /&gt;maxHotIdleSecs = 86400&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxHotSpanSecs = 7776000&lt;BR /&gt;maxMemMB = 20&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxMetaEntries = 1000000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxRunningProcessGroups = 8&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxTimeUnreplicatedNoAcks = 300&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxTimeUnreplicatedWithAcks = 60&lt;BR /&gt;maxTotalDataSizeMB = 76800&lt;BR /&gt;maxWarmDBCount = 200&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf memPoolMB = auto&lt;BR /&gt;minHotIdleSecsBeforeForceRoll = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf minRawFileSyncSecs = disable&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf minStreamGroupQueueSize = 2000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf partialServiceMetaPeriod = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf processTrackerServiceInterval = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf quarantineFutureSecs = 2592000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf quarantinePastSecs = 77760000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf rawChunkSizeBytes = 131072&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf repFactor = 0&lt;BR /&gt;rotatePeriodInSecs = 60&lt;BR /&gt;rtRouterQueueSize =&lt;BR /&gt;rtRouterThreads =&lt;BR /&gt;selfStorageThreads =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceInactiveIndexesPeriod = 60&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceMetaPeriod = 25&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceOnlyAsNeeded = true&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceSubtaskTimingPeriod = 30&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf splitByIndexKeys =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf streamingTargetTsidxSyncPeriodMsec = 5000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf suppressBannerList =&lt;BR /&gt;suspendHotRollByDeleteQuery = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf sync = 0&lt;BR /&gt;syncMeta = 1&lt;BR /&gt;thawedPath = /mnt/archive_s3/SPLUNK_DB/indexname/thaweddb&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf throttleCheckPeriod = 15&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf timePeriodInSecBeforeTsidxReduction = 604800&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf tsidxReductionCheckPeriodInSec = 600&lt;BR /&gt;tsidxWritingLevel =&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/$_index_name/datamodel_summary&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf warmToColdScript =&lt;/P&gt;&lt;P&gt;I assume this is the issue&amp;nbsp;coldPath.maxDataSizeMB = 0 why skip cold, but not sure.&lt;/P&gt;&lt;P&gt;I appreciated if somebody could fix my settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Nov 2020 11:03:27 GMT</pubDate>
    <dc:creator>norbertt911</dc:creator>
    <dc:date>2020-11-20T11:03:27Z</dc:date>
    <item>
      <title>Data going directly to frozen</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-going-directly-to-frozen/m-p/530186#M89265</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a new index - it's a monster - eating up my disk space. Until I move it to the physical server I need to fix it.&lt;/P&gt;&lt;P&gt;Well, I limited maxTotalDataSizeMB, seem working but the cold storage skipped landed in frozen directly, so I cannot search it.&lt;/P&gt;&lt;P&gt;The hot/warm storage is "local" on VM, the cold, frozen, thawed is an S3.&lt;/P&gt;&lt;P&gt;The optimal idea is 7 days in hot/warm (if over maxTotalDataSizeMB then faster) then go cold for 90 days (no size limit) then thawed for 1 year (no size limit).&lt;/P&gt;&lt;P&gt;here is my current setting&lt;/P&gt;&lt;P&gt;archiver.enableDataArchive = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf archiver.maxDataArchiveRetentionPeriod = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf assureUTF8 = false&lt;BR /&gt;bucketRebuildMemoryHint = 0&lt;BR /&gt;coldPath = /mnt/archive_s3/SPLUNK_DB/indexname/colddb&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf coldPath.maxDataSizeMB = 0&lt;BR /&gt;coldToFrozenDir = /mnt/archive_s3/SPLUNK_DB/indexname/Frozenarchive&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf coldToFrozenScript =&lt;BR /&gt;compressRawdata = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf datatype = event&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf defaultDatabase = main&lt;BR /&gt;enableDataIntegrityControl = 0&lt;BR /&gt;enableOnlineBucketRepair = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf enableRealtimeSearch = true&lt;BR /&gt;enableTsidxReduction = 0&lt;BR /&gt;frozenTimePeriodInSecs = 3024000&lt;BR /&gt;homePath = $SPLUNK_DB/indexname/db&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf homePath.maxDataSizeMB = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketTimeRefreshInterval = 10&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf indexThreads = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf journalCompression = gzip&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxBloomBackfillBucketAge = 30d&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxBucketSizeCacheEntries = 0&lt;BR /&gt;maxConcurrentOptimizes = 6&lt;BR /&gt;maxDataSize = auto_high_volume&lt;BR /&gt;maxGlobalDataSizeMB = 0&lt;BR /&gt;maxHotBuckets = 10&lt;BR /&gt;maxHotIdleSecs = 86400&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxHotSpanSecs = 7776000&lt;BR /&gt;maxMemMB = 20&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxMetaEntries = 1000000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxRunningProcessGroups = 8&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxTimeUnreplicatedNoAcks = 300&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxTimeUnreplicatedWithAcks = 60&lt;BR /&gt;maxTotalDataSizeMB = 76800&lt;BR /&gt;maxWarmDBCount = 200&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf memPoolMB = auto&lt;BR /&gt;minHotIdleSecsBeforeForceRoll = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf minRawFileSyncSecs = disable&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf minStreamGroupQueueSize = 2000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf partialServiceMetaPeriod = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf processTrackerServiceInterval = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf quarantineFutureSecs = 2592000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf quarantinePastSecs = 77760000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf rawChunkSizeBytes = 131072&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf repFactor = 0&lt;BR /&gt;rotatePeriodInSecs = 60&lt;BR /&gt;rtRouterQueueSize =&lt;BR /&gt;rtRouterThreads =&lt;BR /&gt;selfStorageThreads =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceInactiveIndexesPeriod = 60&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceMetaPeriod = 25&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceOnlyAsNeeded = true&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceSubtaskTimingPeriod = 30&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf splitByIndexKeys =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf streamingTargetTsidxSyncPeriodMsec = 5000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf suppressBannerList =&lt;BR /&gt;suspendHotRollByDeleteQuery = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf sync = 0&lt;BR /&gt;syncMeta = 1&lt;BR /&gt;thawedPath = /mnt/archive_s3/SPLUNK_DB/indexname/thaweddb&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf throttleCheckPeriod = 15&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf timePeriodInSecBeforeTsidxReduction = 604800&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf tsidxReductionCheckPeriodInSec = 600&lt;BR /&gt;tsidxWritingLevel =&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/$_index_name/datamodel_summary&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf warmToColdScript =&lt;/P&gt;&lt;P&gt;I assume this is the issue&amp;nbsp;coldPath.maxDataSizeMB = 0 why skip cold, but not sure.&lt;/P&gt;&lt;P&gt;I appreciated if somebody could fix my settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 11:03:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-going-directly-to-frozen/m-p/530186#M89265</guid>
      <dc:creator>norbertt911</dc:creator>
      <dc:date>2020-11-20T11:03:27Z</dc:date>
    </item>
  </channel>
</rss>

