<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tsidxstats?  What is this? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47807#M470</link>
    <description>&lt;P&gt;Are you running enetprise security, PCI, or one of the newer releases of our apps?&lt;/P&gt;

&lt;P&gt;Certain apps are now using TSIDX stats to offer better search acceleration than is possible using either summary indexing or report acceleration.&lt;/P&gt;

&lt;P&gt;One thing you might want to do is search through your schedule searches and look for tscollect.  This is what is populating that directory.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Tscollect"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Tscollect&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 May 2013 20:10:17 GMT</pubDate>
    <dc:creator>okrabbe_splunk</dc:creator>
    <dc:date>2013-05-28T20:10:17Z</dc:date>
    <item>
      <title>tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47805#M468</link>
      <description>&lt;P&gt;Our search heads are filling up with tsidx files in the /var/run/splunk/dispatch/tsidxstats directory, but I am not able to find any documentation that explains what these files are.  We suspect that they are search artifacts/results, but could this be summarized data?&lt;/P&gt;

&lt;P&gt;I know that the location of these files can be changed in the indexes.conf, but I am unsure what they are and large they can be.  We have seen as much as 600GB on one search head.  I can resize the space we have alloted for our search head, but I have no idea how big it needs to be.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2013 17:09:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47805#M468</guid>
      <dc:creator>pvols1979</dc:creator>
      <dc:date>2013-05-28T17:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47806#M469</link>
      <description>&lt;P&gt;I believe that these are the files for Report Acceleration Summaries. You should be able to manage them by going to &lt;STRONG&gt;Manager » Report Acceleration Summaries&lt;/STRONG&gt;. If there are some that have never been used, you can just delete them.&lt;BR /&gt;
This will turn off Report Acceleration in the associated reports, so the acceleration summaries will not be re-created.&lt;/P&gt;

&lt;P&gt;Here is some of the documentation on &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Manageacceleratedsearchsummaries"&gt;Report Acceleration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2013 19:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47806#M469</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-05-28T19:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47807#M470</link>
      <description>&lt;P&gt;Are you running enetprise security, PCI, or one of the newer releases of our apps?&lt;/P&gt;

&lt;P&gt;Certain apps are now using TSIDX stats to offer better search acceleration than is possible using either summary indexing or report acceleration.&lt;/P&gt;

&lt;P&gt;One thing you might want to do is search through your schedule searches and look for tscollect.  This is what is populating that directory.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Tscollect"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/SearchReference/Tscollect&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2013 20:10:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47807#M470</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2013-05-28T20:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47808#M471</link>
      <description>&lt;P&gt;TSIDX is similar to summary indexing that allows dramatically improved performance. It is used in several applications such as Enterprise Security (version 2.4 and later). This feature was first available in Splunk 5.0.&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2013 21:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47808#M471</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2013-05-28T21:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47809#M472</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Any idea how to rotate or manage these files? They're filling up seach heads. Do they expire and can it be set somewhere?&lt;/P&gt;

&lt;P&gt;T&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2013 09:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47809#M472</guid>
      <dc:creator>tkiss</dc:creator>
      <dc:date>2013-05-31T09:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47810#M473</link>
      <description>&lt;P&gt;Are you running Enterprise Security? I ask because Enterprise Security has a system built-in to limit the size of the files based on a retention policy. You can modify the retention policy to reduce the size.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2013 16:13:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47810#M473</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2013-05-31T16:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47811#M474</link>
      <description>&lt;P&gt;Check out the Manage Report Acceleration documentation (&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Manageacceleratedsearchsummaries"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Manageacceleratedsearchsummaries&lt;/A&gt;) and this page on Setting the Summary Time Range&lt;BR /&gt;
(&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Manageacceleratedsearchsummaries#Set_report_acceleration_summary_time_ranges"&gt;http://docs.splunk.com/Documentation/Splunk/5.0.2/Knowledge/Manageacceleratedsearchsummaries#Set_report_acceleration_summary_time_ranges&lt;/A&gt;)&lt;/P&gt;

&lt;P&gt;When someone sets up a summary, they also set a time range (7 days, 30 days, etc) for which the acceleration summary will be kept. You can reduce this range to reduce the size of the summary - but you need to do it for each report that uses the summary.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2013 02:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47811#M474</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-06-01T02:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47812#M475</link>
      <description>&lt;P&gt;If these are on the SH I don't think they are report acceleration summaries.&lt;/P&gt;

&lt;P&gt;See Luke Murphey's answer..&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2013 22:05:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47812#M475</guid>
      <dc:creator>okrabbe_splunk</dc:creator>
      <dc:date>2013-06-02T22:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47813#M476</link>
      <description>&lt;P&gt;I suggest that you test by creating some acceleration summaries for youself. At this time, acceleration summaries live on the search head (sadly) as txidx files. You are right that this is not the only way to get tsidx files though.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2013 18:55:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47813#M476</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-06-08T18:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47814#M477</link>
      <description>&lt;P&gt;TSIDX namespace-&lt;BR /&gt;&lt;BR /&gt;
I contributed to a namespace by running index=_* | fields action | tscollect namespace=myaction. &lt;BR /&gt;
This created a myaction folder with a time series file under $SPLUNK_HOME/var/lib/splunk/tsidxstats.&lt;BR /&gt;
My dashboard runs searches against this namespace by running | tstats count from myaction groupby action.  &lt;/P&gt;

&lt;P&gt;Report Acceleration-&lt;BR /&gt;&lt;BR /&gt;
The report acceleration summary is actually a tsidx file created with and rolls with the buckets. ie $SPLUNK_HOME/var/lib/splunk/defaultdb/hot_v1_1&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:47:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47814#M477</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2020-09-28T14:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47815#M478</link>
      <description>&lt;P&gt;No, report acceleration data lives within the $SPLUNK_DB hierarchy, alongside the indexes themselves.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2013 19:36:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47815#M478</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-09-17T19:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47816#M479</link>
      <description>&lt;P&gt;Ah the reason is because you are using a wild card in your index=_* so it's saving the tsidx locally in var/lib so you probably want to change this around and use the Splunk_Internal Messages Data Model for your dashboard queries. That has a lot of the _internal info you maybe looking for. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 18:45:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47816#M479</guid>
      <dc:creator>mcronkrite</dc:creator>
      <dc:date>2020-09-28T18:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: tsidxstats?  What is this?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47817#M480</link>
      <description>&lt;P&gt;Looks like mine are coming from the NetApp Ontap app and are being stored on the search head with the app.&lt;/P&gt;

&lt;P&gt;2.1G    /local/splunk/var/lib/splunk/tsidxstats/netapp_perf_aggr&lt;BR /&gt;
53G     /local/splunk/var/lib/splunk/tsidxstats/netapp_perf_disk&lt;BR /&gt;
14G     /local/splunk/var/lib/splunk/tsidxstats/netapp_perf_lun&lt;BR /&gt;
9.7G    /local/splunk/var/lib/splunk/tsidxstats/netapp_perf_volume&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:20:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tsidxstats-What-is-this/m-p/47817#M480</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2020-09-29T07:20:23Z</dc:date>
    </item>
  </channel>
</rss>

