<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index isn't shrinking when configuring Index size in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361273#M92899</link>
    <description>&lt;P&gt;That was it. Total noob mistake on my part. Didn't realize it was also configured in:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/system/local/indexes.conf &lt;/P&gt;</description>
    <pubDate>Thu, 22 Jun 2017 19:23:25 GMT</pubDate>
    <dc:creator>gingerpower121</dc:creator>
    <dc:date>2017-06-22T19:23:25Z</dc:date>
    <item>
      <title>Index isn't shrinking when configuring Index size</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361271#M92897</link>
      <description>&lt;P&gt;I have the app Splunk_TA_microsoft_ad and I am trying to reduce the storage size of the index "wineventlog" from 50gb to around 15-20gb. I have tried updating the index in the GUI through the indexes page and updating the indexes.conf file and nothing seems to update. I've updated the indexes.conf file below with the config below and restarted splunk service.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;/opt/splunk/etc/apps/Splunk_TA_microsoft_ad/local/indexes.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;My config looks like this:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;[wineventlog]&lt;BR /&gt;
bucketRebuildMemoryHint = 0&lt;BR /&gt;
compressRawdata = 1&lt;BR /&gt;
enableDataIntegrityControl = 0&lt;BR /&gt;
enableOnlineBucketRepair = 1&lt;BR /&gt;
enableTsidxReduction = 0&lt;BR /&gt;
maxTotalDataSizeMB = 15360&lt;BR /&gt;
minHotIdleSecsBeforeForceRoll = 0&lt;BR /&gt;
rtRouterQueueSize =&lt;BR /&gt;
rtRouterThreads =&lt;BR /&gt;
suspendHotRollByDeleteQuery = 0&lt;BR /&gt;
syncMeta = 1&lt;BR /&gt;
maxDataSize = 5120&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:33:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361271#M92897</guid>
      <dc:creator>gingerpower121</dc:creator>
      <dc:date>2020-09-29T14:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: Index isn't shrinking when configuring Index size</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361272#M92898</link>
      <description>&lt;P&gt;Is indexes.conf only defined in one place? When you say "it doesn't update," I assume that you mean that your changes are saved in the file, but that nothing actually changes the size of the index.&lt;/P&gt;

&lt;P&gt;I suggest that you check&lt;BR /&gt;
1. &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Wheretofindtheconfigurationfiles"&gt;Configuration file precedence&lt;/A&gt; - if indexes.conf is defined in multiple places, overlapping definitions are resolved based on the rules of precedence&lt;BR /&gt;
2. Do you need to restart Splunk? When you manually edit indexes.conf, you need to restart Splunk for the changes to take effect.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 18:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361272#M92898</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-06-22T18:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Index isn't shrinking when configuring Index size</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361273#M92899</link>
      <description>&lt;P&gt;That was it. Total noob mistake on my part. Didn't realize it was also configured in:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/system/local/indexes.conf &lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 19:23:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361273#M92899</guid>
      <dc:creator>gingerpower121</dc:creator>
      <dc:date>2017-06-22T19:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Index isn't shrinking when configuring Index size</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361274#M92900</link>
      <description>&lt;P&gt;Everybody does it. Some of us do it more than once!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 20:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-isn-t-shrinking-when-configuring-Index-size/m-p/361274#M92900</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2017-06-22T20:39:54Z</dc:date>
    </item>
  </channel>
</rss>

