<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable a index temporarily in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424433#M5658</link>
    <description>&lt;P&gt;So the events dont drop , are they still queued ? .If I want to ignore them and only get those events from the time it is enabled ,how can I do that&lt;/P&gt;</description>
    <pubDate>Thu, 13 Jun 2019 14:29:04 GMT</pubDate>
    <dc:creator>vrmandadi</dc:creator>
    <dc:date>2019-06-13T14:29:04Z</dc:date>
    <item>
      <title>How to disable an index temporarily?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424423#M5648</link>
      <description>&lt;P&gt;I have an index that I want to disable for some time as a large amount of data is coming from it and it caused a license warning.&lt;/P&gt;
&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 22:57:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424423#M5648</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2020-06-11T22:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424424#M5649</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/RemovedatafromSplunk#Disable_an_index_without_removing_it"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/RemovedatafromSplunk#Disable_an_index_without_removing_it&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 16:17:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424424#M5649</guid>
      <dc:creator>hmarkus</dc:creator>
      <dc:date>2019-06-12T16:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424425#M5650</link>
      <description>&lt;P&gt;@vrmandadi In your indexes.conf under your index stanza , just add &lt;CODE&gt;disabled = true&lt;/CODE&gt;.&lt;BR /&gt;
Or via UI go to Indexes -&amp;gt; Action -&amp;gt; Disable&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 16:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424425#M5650</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-06-12T16:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424426#M5651</link>
      <description>&lt;P&gt;Hello @hmarkus &lt;/P&gt;

&lt;P&gt;Thank you for your mail .We have a indexer cluster so on which box do I need to disable it.If I want to disable via CLI .What is that I need to add to that index is it enabled = 1 for that index&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 21:49:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424426#M5651</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2019-06-12T21:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424427#M5652</link>
      <description>&lt;P&gt;Thank You for you response .Does this setting helps to reduce the license usage?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 21:50:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424427#M5652</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2019-06-12T21:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424428#M5653</link>
      <description>&lt;P&gt;If the data is not indexed it won’t be counted against license . &lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 21:53:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424428#M5653</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-06-12T21:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424429#M5654</link>
      <description>&lt;P&gt;Thank you.So disabling will not get indexed right?..Just to confirm&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 01:08:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424429#M5654</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2019-06-13T01:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424430#M5655</link>
      <description>&lt;P&gt;Yes it won’t get indexed.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 01:29:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424430#M5655</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-06-13T01:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424431#M5656</link>
      <description>&lt;P&gt;Also if you have the index enabled again then any data queued up in forwarder will get indexed to it .&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 01:38:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424431#M5656</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2019-06-13T01:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424432#M5657</link>
      <description>&lt;P&gt;As @Vijeta mentioned, you can also disable it by adding the disabled = true to your indexes.conf. &lt;BR /&gt;
In an index cluster I would add the line in the indexes.conf in your app on the Cluster Master, that is used to configure all indexes in your Cluster (in $SPLUNK_HOME/etc/master-apps/), and than push your new configuration bundle.&lt;BR /&gt;
On a single instance you could use the CLI&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 07:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424432#M5657</guid>
      <dc:creator>hmarkus</dc:creator>
      <dc:date>2019-06-13T07:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424433#M5658</link>
      <description>&lt;P&gt;So the events dont drop , are they still queued ? .If I want to ignore them and only get those events from the time it is enabled ,how can I do that&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 14:29:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424433#M5658</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2019-06-13T14:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424434#M5659</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/179987/if-i-disable-an-index-will-events-for-that-index-s.html"&gt;https://answers.splunk.com/answers/179987/if-i-disable-an-index-will-events-for-that-index-s.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 14:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424434#M5659</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2019-06-13T14:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable a index temporarily</title>
      <link>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424435#M5660</link>
      <description>&lt;P&gt;@hmarkus  .Thank you for your reply .Once I enable back do i get the old events that were already indexed and do I get the data during the index disabled time .&lt;/P&gt;

&lt;P&gt;If I want to ignore the data which is queued ,how can I do that and I do get the data whihc was indexed before the index is disabled right?&lt;/P&gt;

&lt;P&gt;Thanks in Advance&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 14:39:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-disable-an-index-temporarily/m-p/424435#M5660</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2019-06-13T14:39:28Z</dc:date>
    </item>
  </channel>
</rss>

