<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why Splunk did not warn when running out log size? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355358#M8891</link>
    <description>&lt;P&gt;SPlunk has retention period and allocated storage as. ..there are fields called max-daily usages, etc ...yes i lost data otherwise i would not raise this question.... &lt;/P&gt;

&lt;P&gt;Max-daily usage is 5GB if you go above that then u will lose data..i'm about sure about Splunk version&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2017 04:38:12 GMT</pubDate>
    <dc:creator>jw44250</dc:creator>
    <dc:date>2017-06-16T04:38:12Z</dc:date>
    <item>
      <title>Why Splunk did not warn when running out log size?</title>
      <link>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355356#M8889</link>
      <description>&lt;P&gt;I have 5GB size max per day for a log (s). went above it almost 8 but lost the earliest data. in any file system if there is no space you will get warning but u will not lose your data....for example ...let say having folder in window, linux with 200MB occupied, when the next data is added -- warnig will pop up with some message..&lt;/P&gt;

&lt;P&gt;I am not sure about how SPlunk does it..but i think ...what it does..the data is arranged in term of bucket and each bucket has four stages warn--&amp;gt;cold--&amp;gt; hot--&amp;gt; frozen... the data will moved with these stages now and than the old data that x bucket will be replaced with new data so the existing data is lost ...to increase 5GB to 10GB - 20 GB what is the point ...again it can happend...&lt;/P&gt;

&lt;P&gt;Guys -- I am not Splunk Admin...just normal user. but I dont get a good answer so far... &lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 00:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355356#M8889</guid>
      <dc:creator>jw44250</dc:creator>
      <dc:date>2017-06-16T00:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why Splunk did not warn when running out log size?</title>
      <link>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355357#M8890</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;the data is arranged in term of bucket and each bucket has four stages warn--&amp;gt;cold--&amp;gt; hot--&amp;gt; frozen   &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;the correct four stages are hot---&amp;gt; warm ---&amp;gt; cold ---&amp;gt; frozen.&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;I have 5GB size max per day for a log (s). went above it almost 8 but lost the earliest data.&lt;BR /&gt;
you mean the daily license limit of 5GB ? or some other log limit? &lt;BR /&gt;
maybe, you have not lost any data. (just not able to search, maybe)&lt;BR /&gt;
also, what version of Splunk? &lt;BR /&gt;
this issue is bit confusing.. some more clear info please. &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 16 Jun 2017 01:34:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355357#M8890</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-06-16T01:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why Splunk did not warn when running out log size?</title>
      <link>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355358#M8891</link>
      <description>&lt;P&gt;SPlunk has retention period and allocated storage as. ..there are fields called max-daily usages, etc ...yes i lost data otherwise i would not raise this question.... &lt;/P&gt;

&lt;P&gt;Max-daily usage is 5GB if you go above that then u will lose data..i'm about sure about Splunk version&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 04:38:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355358#M8891</guid>
      <dc:creator>jw44250</dc:creator>
      <dc:date>2017-06-16T04:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why Splunk did not warn when running out log size?</title>
      <link>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355359#M8892</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;Max-daily usage is 5GB if you go above that then u will lose data &lt;BR /&gt;
seems like, daily license limit is 5GB and if you go above the 5GB, you will get license warning, data will be still indexed. &lt;BR /&gt;
i'm about sure about Splunk version &lt;BR /&gt;
i think you mistyped. to check your splunk version, on the login screen, lower part you could see like - &lt;BR /&gt;
"@ 2005-2017 Splunk Inc. Splunk 6.3.4 build cae2458f4aef " &lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 16 Jun 2017 05:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355359#M8892</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2017-06-16T05:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why Splunk did not warn when running out log size?</title>
      <link>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355360#M8893</link>
      <description>&lt;P&gt;© 2005-2017 Splunk Inc. All rights reserved.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 17:00:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355360#M8893</guid>
      <dc:creator>jw44250</dc:creator>
      <dc:date>2017-06-16T17:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Why Splunk did not warn when running out log size?</title>
      <link>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355361#M8894</link>
      <description>&lt;P&gt;Splunk Version 6.5.2.1&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2017 17:01:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Why-Splunk-did-not-warn-when-running-out-log-size/m-p/355361#M8894</guid>
      <dc:creator>jw44250</dc:creator>
      <dc:date>2017-06-16T17:01:37Z</dc:date>
    </item>
  </channel>
</rss>

