<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Freeing up Splunk system disk space in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634950#M9415</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237560"&gt;@DCUsupport&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know why this parameter is configurable only by conf file and not by GUI, so you have to add the row in each stanza of your indexes.conf file.&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said, don't modify conf files in default folders: copy and modify them in local folders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 17 Mar 2023 16:07:30 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-03-17T16:07:30Z</dc:date>
    <item>
      <title>Is it possible to free up Splunk system disk space?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634405#M9396</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know it's possible to remove things from Splunk search that are older than two years, for example. If I apply this setting, space is not freed on the system disk where Splunk is installed.&lt;BR /&gt;Therefore, I am asking for information on how to delete data older than two years from Splunk DB, so as to free up space on the system disk.&lt;BR /&gt;Is it even possible?&lt;BR /&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;DCUsupport&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 16:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634405#M9396</guid>
      <dc:creator>DCUsupport</dc:creator>
      <dc:date>2023-03-15T16:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634408#M9397</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237560"&gt;@DCUsupport&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;by default, retention is defined in 6 years, but you can configure retention adding the "&lt;SPAN&gt;frozenTimePeriodInSecs" option to the indexes to reduce (in indexes.conf).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I hint to start from _internal that's very verbose and old data aren't so useful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But anyway, you should configure retention for all your indexes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 13:14:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634408#M9397</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-14T13:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634429#M9398</link>
      <description>&lt;P&gt;1. Verify what is using up your space&lt;/P&gt;&lt;P&gt;2. If these are indexes, check their parameters and possibly lower the limits (time limit for freezing and size limits for indexes; you can also define volume and set overall limit for the whole volume)&lt;/P&gt;&lt;P&gt;3. If these are not indexes, check where they come from. Course of action will depend on what it is.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 15:23:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634429#M9398</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-14T15:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634885#M9405</link>
      <description>&lt;P&gt;Hello PickleRick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;occupied space size in KB:&lt;/P&gt;&lt;P&gt;296400092 KB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /opt/splunk/var&lt;/P&gt;&lt;P&gt;292801716 KB&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /opt/splunk/var/lib/splunk&lt;/P&gt;&lt;P&gt;4340556 /opt/splunk/var/lib/splunk/audit&lt;/P&gt;&lt;P&gt;64037852&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /opt/splunk/var/lib/splunk/defaultdb&lt;/P&gt;&lt;P&gt;468520&amp;nbsp; /opt/splunk/var/lib/splunk/fishbucket&lt;/P&gt;&lt;P&gt;198205448&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /opt/splunk/var/lib/splunk/fortigate&lt;/P&gt;&lt;P&gt;3017864 /opt/splunk/var/lib/splunk/_internaldb&lt;/P&gt;&lt;P&gt;2622968 /opt/splunk/var/lib/splunk/_introspection&lt;/P&gt;&lt;P&gt;596772&amp;nbsp; /opt/splunk/var/lib/splunk/kvstore&lt;/P&gt;&lt;P&gt;851316&amp;nbsp; /opt/splunk/var/lib/splunk/_metrics&lt;/P&gt;&lt;P&gt;18631936&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /opt/splunk/var/lib/splunk/os&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know how to find out if they are indexes or not.&lt;BR /&gt;I am asking for information on how to recognize this, or where I should reduce the limits for indexes. I could not find indexes.conf.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 09:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634885#M9405</guid>
      <dc:creator>DCUsupport</dc:creator>
      <dc:date>2023-03-17T09:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to free up Splunk system disk space?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634887#M9407</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the indexes.conf, but I'm not very smart about setting it up. It probably looks like the retention period is 2 years if I understand correctly. But I don't know how to proceed further.&lt;BR /&gt;The full listing of indexes.conf can be found below.&lt;/P&gt;&lt;P&gt;#Version 8.2.3&lt;BR /&gt;#DO NOT EDIT THIS FILE!&lt;BR /&gt;# Changes to default files will be lost on update and are difficult to&lt;BR /&gt;# manage and support.&lt;BR /&gt;#&lt;BR /&gt;# Please make any changes to system defaults by overriding them in&lt;BR /&gt;# apps or $SPLUNK_HOME/etc/system/local&lt;BR /&gt;# (See "Configuration file precedence" in the web documentation).&lt;BR /&gt;#&lt;BR /&gt;# To override a specific setting, copy the name of the stanza and&lt;BR /&gt;# setting to the file where you wish to override it.&lt;BR /&gt;#&lt;BR /&gt;# This file configures Splunk's indexes and their properties.&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;################################################################################&lt;BR /&gt;# "global" params (not specific to individual indexes)&lt;BR /&gt;################################################################################&lt;BR /&gt;sync = 0&lt;BR /&gt;indexThreads = auto&lt;BR /&gt;memPoolMB = auto&lt;BR /&gt;defaultDatabase = main&lt;BR /&gt;enableRealtimeSearch = true&lt;BR /&gt;suppressBannerList =&lt;BR /&gt;maxRunningProcessGroups = 8&lt;BR /&gt;maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;bucketRebuildMemoryHint = auto&lt;BR /&gt;serviceOnlyAsNeeded = true&lt;BR /&gt;serviceSubtaskTimingPeriod = 30&lt;BR /&gt;serviceInactiveIndexesPeriod = 60&lt;BR /&gt;maxBucketSizeCacheEntries = 0&lt;BR /&gt;processTrackerServiceInterval = 1&lt;BR /&gt;hotBucketTimeRefreshInterval = 10&lt;BR /&gt;rtRouterThreads = 0&lt;BR /&gt;rtRouterQueueSize = 10000&lt;BR /&gt;selfStorageThreads = 2&lt;BR /&gt;fileSystemExecutorWorkers = 5&lt;BR /&gt;hotBucketStreaming.extraBucketBuildingCmdlineArgs =&lt;/P&gt;&lt;P&gt;################################################################################&lt;BR /&gt;# index specific defaults&lt;BR /&gt;################################################################################&lt;BR /&gt;maxDataSize = auto&lt;BR /&gt;maxWarmDBCount = 300&lt;BR /&gt;frozenTimePeriodInSecs = 188697600&lt;BR /&gt;rotatePeriodInSecs = 60&lt;BR /&gt;coldToFrozenScript =&lt;BR /&gt;coldToFrozenDir =&lt;BR /&gt;compressRawdata = true&lt;BR /&gt;maxTotalDataSizeMB = 500000&lt;BR /&gt;maxGlobalRawDataSizeMB = 0&lt;BR /&gt;maxGlobalDataSizeMB = 0&lt;BR /&gt;maxMemMB = 5&lt;BR /&gt;maxConcurrentOptimizes = 6&lt;BR /&gt;maxHotSpanSecs = 7776000&lt;BR /&gt;maxHotIdleSecs = 0&lt;BR /&gt;maxHotBuckets = auto&lt;BR /&gt;metric.maxHotBuckets = auto&lt;BR /&gt;minHotIdleSecsBeforeForceRoll = auto&lt;BR /&gt;quarantinePastSecs = 77760000&lt;BR /&gt;quarantineFutureSecs = 2592000&lt;BR /&gt;rawChunkSizeBytes = 131072&lt;BR /&gt;minRawFileSyncSecs = disable&lt;BR /&gt;assureUTF8 = false&lt;BR /&gt;serviceMetaPeriod = 25&lt;BR /&gt;partialServiceMetaPeriod = 0&lt;BR /&gt;throttleCheckPeriod = 15&lt;BR /&gt;syncMeta = true&lt;BR /&gt;maxMetaEntries = 1000000&lt;BR /&gt;maxBloomBackfillBucketAge = 30d&lt;BR /&gt;enableOnlineBucketRepair = true&lt;BR /&gt;enableDataIntegrityControl = false&lt;BR /&gt;maxTimeUnreplicatedWithAcks = 60&lt;BR /&gt;maxTimeUnreplicatedNoAcks = 300&lt;BR /&gt;minStreamGroupQueueSize = 2000&lt;BR /&gt;warmToColdScript=&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/$_index_name/datamodel_summary&lt;BR /&gt;homePath.maxDataSizeMB = 0&lt;BR /&gt;coldPath.maxDataSizeMB = 0&lt;BR /&gt;streamingTargetTsidxSyncPeriodMsec = 5000&lt;BR /&gt;journalCompression = gzip&lt;BR /&gt;enableTsidxReduction = false&lt;BR /&gt;suspendHotRollByDeleteQuery = false&lt;BR /&gt;tsidxReductionCheckPeriodInSec = 600&lt;BR /&gt;timePeriodInSecBeforeTsidxReduction = 604800&lt;BR /&gt;datatype = event&lt;BR /&gt;splitByIndexKeys =&lt;BR /&gt;metric.splitByIndexKeys =&lt;BR /&gt;tsidxWritingLevel = 2&lt;BR /&gt;archiver.enableDataArchive = false&lt;BR /&gt;archiver.maxDataArchiveRetentionPeriod = 0&lt;BR /&gt;hotBucketStreaming.sendSlices = false&lt;BR /&gt;hotBucketStreaming.removeRemoteSlicesOnRoll = false&lt;BR /&gt;hotBucketStreaming.reportStatus = false&lt;BR /&gt;hotBucketStreaming.deleteHotsAfterRestart = false&lt;BR /&gt;tsidxDedupPostingsListMaxTermsLimit = 8388608&lt;BR /&gt;tsidxTargetSizeMB = 1500&lt;BR /&gt;metric.tsidxTargetSizeMB = 1500&lt;BR /&gt;metric.enableFloatingPointCompression = true&lt;BR /&gt;metric.compressionBlockSize = 1024&lt;BR /&gt;metric.stubOutRawdataJournal = true&lt;BR /&gt;metric.timestampResolution = s&lt;BR /&gt;waitPeriodInSecsForManifestWrite = 60&lt;BR /&gt;bucketMerging = false&lt;BR /&gt;bucketMerge.minMergeSizeMB = 750&lt;BR /&gt;bucketMerge.maxMergeSizeMB = 1000&lt;BR /&gt;bucketMerge.maxMergeTimeSpanSecs = 7776000&lt;/P&gt;&lt;P&gt;#&lt;BR /&gt;# By default none of the indexes are replicated.&lt;BR /&gt;#&lt;BR /&gt;repFactor = 0&lt;/P&gt;&lt;P&gt;# Splunk to Splunk federated index&lt;BR /&gt;federated.provider =&lt;BR /&gt;federated.dataset =&lt;/P&gt;&lt;P&gt;[volume:_splunk_summaries]&lt;BR /&gt;path = $SPLUNK_DB&lt;/P&gt;&lt;P&gt;[provider-family:hadoop]&lt;BR /&gt;vix.mode = report&lt;BR /&gt;vix.command = $SPLUNK_HOME/bin/jars/sudobash&lt;BR /&gt;vix.command.arg.1 = $HADOOP_HOME/bin/hadoop&lt;BR /&gt;vix.command.arg.2 = jar&lt;BR /&gt;vix.command.arg.3 = $SPLUNK_HOME/bin/jars/SplunkMR-h1.jar&lt;BR /&gt;vix.command.arg.4 = com.splunk.mr.SplunkMR&lt;BR /&gt;vix.env.MAPREDUCE_USER =&lt;BR /&gt;vix.env.HADOOP_HEAPSIZE = 512&lt;BR /&gt;vix.env.HADOOP_CLIENT_OPTS = -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.env.HUNK_THIRDPARTY_JARS = $SPLUNK_HOME/bin/jars/thirdparty/common/avro-1.7.7.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/avro-mapred-1.7.7.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/commons-compress-1.21.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/commons-io-2.4.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/libfb303-0.9.2.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/parquet-hive-bundle-1.10.1.jar,$SPLUNK_HOME/bin/jars/thirdparty/common/snappy-java-1.1.1.7.jar,$SPLUNK_HOME/bin/jars/thirdparty/hive/hive-exec-0.12.0.jar,$SPLUNK_HOME/bin/jars/thirdparty/hive/hive-metastore-0.12.0.jar,$SPLUNK_HOME/bin/jars/thirdparty/hive/hive-serde-0.12.0.jar&lt;BR /&gt;vix.mapred.job.reuse.jvm.num.tasks = 100&lt;BR /&gt;vix.mapred.child.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.mapred.reduce.tasks = 0&lt;BR /&gt;vix.mapred.job.map.memory.mb = 2048&lt;BR /&gt;vix.mapred.job.reduce.memory.mb = 512&lt;BR /&gt;vix.mapred.job.queue.name = default&lt;BR /&gt;vix.mapreduce.job.jvm.numtasks = 100&lt;BR /&gt;vix.mapreduce.map.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.mapreduce.reduce.java.opts = -server -Xmx512m -XX:ParallelGCThreads=4 -XX:+UseParallelGC -XX:+DisplayVMOutputToStderr&lt;BR /&gt;vix.mapreduce.job.reduces = 0&lt;BR /&gt;vix.mapreduce.map.memory.mb = 2048&lt;BR /&gt;vix.mapreduce.reduce.memory.mb = 512&lt;BR /&gt;vix.mapreduce.job.queuename = default&lt;BR /&gt;vix.splunk.search.column.filter = 1&lt;BR /&gt;vix.splunk.search.mixedmode = 1&lt;BR /&gt;vix.splunk.search.debug = 0&lt;BR /&gt;vix.splunk.search.mr.maxsplits = 10000&lt;BR /&gt;vix.splunk.search.mr.minsplits = 100&lt;BR /&gt;vix.splunk.search.mr.splits.multiplier = 10&lt;BR /&gt;vix.splunk.search.mr.poll = 2000&lt;BR /&gt;vix.splunk.search.recordreader = SplunkJournalRecordReader,ValueAvroRecordReader,SimpleCSVRecordReader,SequenceFileRecordReader&lt;BR /&gt;vix.splunk.search.recordreader.avro.regex = \.avro$&lt;BR /&gt;vix.splunk.search.recordreader.csv.regex = \.([tc]sv)(?:\.(?:gz|bz2|snappy))?$&lt;BR /&gt;vix.splunk.search.recordreader.sequence.regex = \.seq$&lt;BR /&gt;vix.splunk.home.datanode = /tmp/splunk/$SPLUNK_SERVER_NAME/&lt;BR /&gt;vix.splunk.heartbeat = 1&lt;BR /&gt;vix.splunk.heartbeat.threshold = 60&lt;BR /&gt;vix.splunk.heartbeat.interval = 1000&lt;BR /&gt;vix.splunk.setup.onsearch = 1&lt;BR /&gt;vix.splunk.setup.package = current&lt;/P&gt;&lt;P&gt;################################################################################&lt;BR /&gt;# index definitions&lt;BR /&gt;################################################################################&lt;/P&gt;&lt;P&gt;[main]&lt;BR /&gt;homePath = $SPLUNK_DB/defaultdb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/defaultdb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/defaultdb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/defaultdb/datamodel_summary&lt;BR /&gt;maxMemMB = 20&lt;BR /&gt;maxConcurrentOptimizes = 6&lt;BR /&gt;maxHotIdleSecs = 86400&lt;BR /&gt;maxHotBuckets = 10&lt;BR /&gt;maxDataSize = auto_high_volume&lt;/P&gt;&lt;P&gt;[history]&lt;BR /&gt;homePath = $SPLUNK_DB/historydb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/historydb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/historydb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/historydb/datamodel_summary&lt;BR /&gt;maxDataSize = 10&lt;BR /&gt;frozenTimePeriodInSecs = 604800&lt;/P&gt;&lt;P&gt;[summary]&lt;BR /&gt;homePath = $SPLUNK_DB/summarydb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/summarydb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/summarydb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/summarydb/datamodel_summary&lt;/P&gt;&lt;P&gt;[_internal]&lt;BR /&gt;homePath = $SPLUNK_DB/_internaldb/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_internaldb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_internaldb/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/_internaldb/datamodel_summary&lt;BR /&gt;maxDataSize = 1000&lt;BR /&gt;maxHotSpanSecs = 432000&lt;BR /&gt;frozenTimePeriodInSecs = 2592000&lt;/P&gt;&lt;P&gt;[_audit]&lt;BR /&gt;homePath = $SPLUNK_DB/audit/db&lt;BR /&gt;coldPath = $SPLUNK_DB/audit/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/audit/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/audit/datamodel_summary&lt;/P&gt;&lt;P&gt;[_thefishbucket]&lt;BR /&gt;homePath = $SPLUNK_DB/fishbucket/db&lt;BR /&gt;coldPath = $SPLUNK_DB/fishbucket/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/fishbucket/thaweddb&lt;BR /&gt;tstatsHomePath = volume:_splunk_summaries/fishbucket/datamodel_summary&lt;BR /&gt;maxDataSize = 500&lt;BR /&gt;frozenTimePeriodInSecs = 2419200&lt;/P&gt;&lt;P&gt;# this index has been removed in the 4.1 series, but this stanza must be&lt;BR /&gt;# preserved to avoid displaying errors for users that have tweaked the index's&lt;BR /&gt;# size/etc parameters in local/indexes.conf.&lt;BR /&gt;#&lt;BR /&gt;[splunklogger]&lt;BR /&gt;homePath = $SPLUNK_DB/splunklogger/db&lt;BR /&gt;coldPath = $SPLUNK_DB/splunklogger/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/splunklogger/thaweddb&lt;BR /&gt;disabled = true&lt;/P&gt;&lt;P&gt;[_introspection]&lt;BR /&gt;homePath = $SPLUNK_DB/_introspection/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_introspection/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_introspection/thaweddb&lt;BR /&gt;maxDataSize = 1024&lt;BR /&gt;frozenTimePeriodInSecs = 1209600&lt;/P&gt;&lt;P&gt;[_telemetry]&lt;BR /&gt;homePath = $SPLUNK_DB/_telemetry/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_telemetry/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_telemetry/thaweddb&lt;BR /&gt;maxDataSize = 256&lt;BR /&gt;frozenTimePeriodInSecs = 63072000&lt;/P&gt;&lt;P&gt;[_metrics]&lt;BR /&gt;homePath = $SPLUNK_DB/_metrics/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_metrics/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_metrics/thaweddb&lt;BR /&gt;datatype = metric&lt;BR /&gt;#14 day retention&lt;BR /&gt;frozenTimePeriodInSecs = 1209600&lt;BR /&gt;metric.splitByIndexKeys = metric_name&lt;/P&gt;&lt;P&gt;# Internal Use Only: rollup data from the _metrics index.&lt;BR /&gt;[_metrics_rollup]&lt;BR /&gt;homePath = $SPLUNK_DB/_metrics_rollup/db&lt;BR /&gt;coldPath = $SPLUNK_DB/_metrics_rollup/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_metrics_rollup/thaweddb&lt;BR /&gt;datatype = metric&lt;BR /&gt;# 2 year retention&lt;BR /&gt;frozenTimePeriodInSecs = 63072000&lt;BR /&gt;metric.splitByIndexKeys = metric_name&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 09:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634887#M9407</guid>
      <dc:creator>DCUsupport</dc:creator>
      <dc:date>2023-03-17T09:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to free up Splunk system disk space?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634902#M9410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237560"&gt;@DCUsupport&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;from the above indexer.conf, list the indexes to reduce.&lt;/P&gt;&lt;P&gt;then create a file in a local folder of your app containing the index names and for each one the option&amp;nbsp;&lt;SPAN&gt;'frozenTimePeriodInSecs'&amp;nbsp;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in other words to have a retention of 30 days for each index you have to setup:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[index1]
frozenTimePeriodInSecs = 2592000
[index2]
frozenTimePeriodInSecs = 2592000
[index3]
frozenTimePeriodInSecs = 2592000&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 11:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634902#M9410</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-17T11:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634908#M9411</link>
      <description>&lt;P&gt;Typically this directory indeed stores indexes. In your case most of the space is used by the fortigate directory (which probably contains an index called, surprise surprise, fortigate) and the defaultdb directory which contains the &lt;EM&gt;main&lt;/EM&gt; index.&lt;/P&gt;&lt;P&gt;1. Don't touch system/default/indexes.conf! Actually, never touch any system/default/ files. If you need to do config adjustments, put them in your app or system/local.&lt;/P&gt;&lt;P&gt;2. Using the &lt;EM&gt;main&lt;/EM&gt; index isn't a very good practice. You should have purpose-created indexes for your data.&lt;/P&gt;&lt;P&gt;3. As &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; already pointed out, the default retention period is 6 years so you might want to tweak that. I suppose you use an all-in-one installation so you can change it in Settings-&amp;gt;Indexes. You can also limit the index by size. But remember that the index directory contains not only index data but can contain - for example - accelerated summaries so that size limiting will not be 100% precise (it isn't anyway XD)&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 13:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634908#M9411</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-17T13:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634949#M9414</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In settings -&amp;gt; indexes I found this, but I don't see the option to adjust retention.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fortigate_splunk.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/24356i99FF1529133FF245/image-size/large?v=v2&amp;amp;px=999" role="button" title="fortigate_splunk.JPG" alt="fortigate_splunk.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I tried looking for config for Fortigate and only found app.conf, TA-FortinetAR.conf, TA-FortinetAR_credential.conf, TA-FortinetAR_customized.conf in /opt/splunk/etc/apps/TA-FortinetAR/local. All contain only the default parameter, except for app.conf which contains:&lt;BR /&gt;[install]&lt;BR /&gt;state = disabled&lt;BR /&gt;is_configured = 0&lt;/P&gt;&lt;P&gt;Is it enough to add the parameter frozenTimePeriodInSecs with its own value to TA-FortinetAR.conf?&lt;/P&gt;&lt;P&gt;Or it's enough for me in indexes.conf&lt;BR /&gt;add this:&lt;/P&gt;&lt;P&gt;[fortigate]&lt;BR /&gt;homePath = $SPLUNK_DB/fortigate/db&lt;BR /&gt;coldPath = $SPLUNK_DB/fortigate/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/fortigate/thaweddb&lt;BR /&gt;maxDataSize = auto_high_volume&lt;BR /&gt;frozenTimePeriodInSecs = 63072000&lt;/P&gt;&lt;P&gt;or something similar?&lt;BR /&gt;If it will be enough and I will set this retention. Will disk space be automatically freed up if there is currently more than two and a half years of data there and the retention will be for two years?&lt;/P&gt;&lt;P&gt;Again, sorry if my questions are wrong. I don't have much experience with Splunk yet.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 16:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634949#M9414</guid>
      <dc:creator>DCUsupport</dc:creator>
      <dc:date>2023-03-17T16:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634950#M9415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237560"&gt;@DCUsupport&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know why this parameter is configurable only by conf file and not by GUI, so you have to add the row in each stanza of your indexes.conf file.&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said, don't modify conf files in default folders: copy and modify them in local folders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 16:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634950#M9415</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-17T16:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634953#M9416</link>
      <description>&lt;P&gt;Hah. I haven't configured indexes via gui for so long that I forgot that indeed the time to frozen is not set there.&lt;/P&gt;&lt;P&gt;The app you mentioned is most probably responsible for parsing the data and maybe displaying it in some dashboards so don't touch it.&lt;/P&gt;&lt;P&gt;Depending on where your fortigate index is defined, it's probably most convenient to adjust the frozenTimePeriodInSecs in the same file.&lt;/P&gt;&lt;P&gt;Just do&lt;/P&gt;&lt;P&gt;splunk btool indexes list fortigate --debug&lt;/P&gt;&lt;P&gt;It will show you in which file(s) settings regarding this file are defined. If there is already the frozenTimePeriodInSecs setting, just edit the file where it's specified and adjust it. If it is not, just edit the file where the setting is defined (don't touch anything from system/default directory!). And add this setting.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 16:11:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634953#M9416</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-17T16:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634961#M9417</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the splunk btool indexes list fortigate --debug command listing below:&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf [fortigate]&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf archiver.enableDataArchive = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf archiver.maxDataArchiveRetentionPeriod = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf assureUTF8 = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf bucketMerge.maxMergeSizeMB = 1000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf bucketMerge.maxMergeTimeSpanSecs = 7776000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf bucketMerge.minMergeSizeMB = 750&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf bucketMerging = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf bucketRebuildMemoryHint = auto&lt;BR /&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf coldPath = $SPLUNK_DB/fortigate/colddb&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf coldPath.maxDataSizeMB = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf coldToFrozenDir =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf coldToFrozenScript =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf compressRawdata = true&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf datatype = event&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf defaultDatabase = main&lt;BR /&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf enableDataIntegrityControl = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf enableOnlineBucketRepair = true&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf enableRealtimeSearch = true&lt;BR /&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf enableTsidxReduction = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf federated.dataset =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf federated.provider =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf fileSystemExecutorWorkers = 5&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf frozenTimePeriodInSecs = 188697600&lt;BR /&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf homePath = $SPLUNK_DB/fortigate/db&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf homePath.maxDataSizeMB = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketStreaming.deleteHotsAfterRestart = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketStreaming.extraBucketBuildingCmdlineArgs =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketStreaming.removeRemoteSlicesOnRoll = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketStreaming.reportStatus = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketStreaming.sendSlices = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf hotBucketTimeRefreshInterval = 10&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf indexThreads = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf journalCompression = gzip&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxBloomBackfillBucketAge = 30d&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxBucketSizeCacheEntries = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxConcurrentOptimizes = 6&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxDataSize = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxGlobalDataSizeMB = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxGlobalRawDataSizeMB = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxHotBuckets = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxHotIdleSecs = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxHotSpanSecs = 7776000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxMemMB = 5&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxMetaEntries = 1000000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxRunningProcessGroups = 8&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxRunningProcessGroupsLowPriority = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxTimeUnreplicatedNoAcks = 300&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxTimeUnreplicatedWithAcks = 60&lt;BR /&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf maxTotalDataSizeMB = 512000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf maxWarmDBCount = 300&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf memPoolMB = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf metric.compressionBlockSize = 1024&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf metric.enableFloatingPointCompression = true&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf metric.maxHotBuckets = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf metric.splitByIndexKeys =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf metric.stubOutRawdataJournal = true&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf metric.timestampResolution = s&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf metric.tsidxTargetSizeMB = 1500&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf minHotIdleSecsBeforeForceRoll = auto&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf minRawFileSyncSecs = disable&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf minStreamGroupQueueSize = 2000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf partialServiceMetaPeriod = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf processTrackerServiceInterval = 1&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf quarantineFutureSecs = 2592000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf quarantinePastSecs = 77760000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf rawChunkSizeBytes = 131072&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf repFactor = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf rotatePeriodInSecs = 60&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf rtRouterQueueSize = 10000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf rtRouterThreads = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf selfStorageThreads = 2&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceInactiveIndexesPeriod = 60&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceMetaPeriod = 25&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceOnlyAsNeeded = true&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf serviceSubtaskTimingPeriod = 30&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf splitByIndexKeys =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf streamingTargetTsidxSyncPeriodMsec = 5000&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf suppressBannerList =&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf suspendHotRollByDeleteQuery = false&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf sync = 0&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf syncMeta = true&lt;BR /&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf thawedPath = $SPLUNK_DB/fortigate/thaweddb&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf throttleCheckPeriod = 15&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf timePeriodInSecBeforeTsidxReduction = 604800&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf tsidxDedupPostingsListMaxTermsLimit = 8388608&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf tsidxReductionCheckPeriodInSec = 600&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf tsidxTargetSizeMB = 1500&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf tsidxWritingLevel = 2&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf tstatsHomePath = volume:_splunk_summaries/$_index_name/datamodel_summary&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf waitPeriodInSecsForManifestWrite = 60&lt;BR /&gt;/opt/splunk/etc/system/default/indexes.conf warmToColdScript =&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;cat /opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf&lt;BR /&gt;[fortigate]&lt;BR /&gt;coldPath = $SPLUNK_DB/fortigate/colddb&lt;BR /&gt;enableDataIntegrityControl = 0&lt;BR /&gt;enableTsidxReduction = 0&lt;BR /&gt;homePath = $SPLUNK_DB/fortigate/db&lt;BR /&gt;maxTotalDataSizeMB = 512000&lt;BR /&gt;thawedPath = $SPLUNK_DB/fortigate/thaweddb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should it be enough to add the parameter frozenTimePeriodInSecs to /opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf ?&lt;BR /&gt;Because it is not populated in /opt/splunk/etc/apps/SplunkAppForFortinet/local/indexes.conf and it seems to take this value from system/default where you have forbidden me to make modifications which I understand &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you for your patience in resolving this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 17:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/634961#M9417</guid>
      <dc:creator>DCUsupport</dc:creator>
      <dc:date>2023-03-17T17:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/635022#M9421</link>
      <description>&lt;P&gt;Yes, that's where the index seems to be configured (apart from the inherited defaults). I'd put the setting there.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 09:42:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/635022#M9421</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-03-18T09:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/635160#M9423</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like it works.&lt;BR /&gt;Thank you so much for your help both.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 15:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/635160#M9423</guid>
      <dc:creator>DCUsupport</dc:creator>
      <dc:date>2023-03-20T15:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Freeing up Splunk system disk space</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/635161#M9424</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237560"&gt;@DCUsupport&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated by all the contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Is-it-possible-to-free-up-Splunk-system-disk-space/m-p/635161#M9424</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-20T16:00:17Z</dc:date>
    </item>
  </channel>
</rss>

