<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Indexes question in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502545#M8887</link>
    <description>&lt;P&gt;What's the setting for sized based rolling? Is it &lt;CODE&gt;maxVolumeDataSizeMB&lt;/CODE&gt;&lt;BR /&gt;
 And if i mention both, who'll take the precedence?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2020 08:24:39 GMT</pubDate>
    <dc:creator>sarwshai</dc:creator>
    <dc:date>2020-03-24T08:24:39Z</dc:date>
    <item>
      <title>Splunk Indexes question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502543#M8885</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;1) I want to move my hot/warm bucket to cold after 90 days, is it possible to roll buckets based on time duration or only can roll volume based? Want to keep Hot and Warm for 90 days as i am using ssd for it and move it to cold in slow disk after that.&lt;/P&gt;

&lt;P&gt;Can this setting be applied&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;maxHotSpanSecs = [90days]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2) Also i intend to keep hot/warm in same path and cold in another, below config is right for the same? Do i need to mention &lt;CODE&gt;volume:&lt;/CODE&gt;&lt;BR /&gt;
 in homepath too(my hot/warm buckets should be in &lt;CODE&gt;/opt/splunk/var/lib/splunk&lt;/CODE&gt;)? &lt;BR /&gt;
3) Also where should be accelelarated(tstats) be stored ideally&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
homePath       = $SPLUNK_DB/$_index_name/db
coldPath       = volume:[cold]/$_index_name/colddb
thawedPath     = $SPLUNK_DB/$_index_name/thaweddb
tstatsHomePath = volume:_splunk_summaries/$_index_name/datamodel_summary
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 15:56:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502543#M8885</guid>
      <dc:creator>sarwshai</dc:creator>
      <dc:date>2020-03-23T15:56:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502544#M8886</link>
      <description>&lt;P&gt;It is never advisable (except in the cases of legal mandates) to use TIME-based settings for &lt;CODE&gt;hot/warm&lt;/CODE&gt; buckets.  If you do, you will find that a significant portion of your FAST &lt;CODE&gt;hot/warm&lt;/CODE&gt; space will be unused AND that you will send WAY too much time administering settings and disk volumes.  Just use SIZE-based settings and keep an eye on &lt;CODE&gt;bucketmover&lt;/CODE&gt; events to see how much is in &lt;CODE&gt;hot/warm&lt;/CODE&gt; so that you know when you should add more disk or indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 17:01:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502544#M8886</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-23T17:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502545#M8887</link>
      <description>&lt;P&gt;What's the setting for sized based rolling? Is it &lt;CODE&gt;maxVolumeDataSizeMB&lt;/CODE&gt;&lt;BR /&gt;
 And if i mention both, who'll take the precedence?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 08:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502545#M8887</guid>
      <dc:creator>sarwshai</dc:creator>
      <dc:date>2020-03-24T08:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502546#M8888</link>
      <description>&lt;P&gt;Yes. That is it.  If you set both, then both work independently and simultaneously.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 14:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502546#M8888</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-24T14:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes question</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502547#M8889</link>
      <description>&lt;P&gt;Thanks @woodcock &lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 14:52:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Indexes-question/m-p/502547#M8889</guid>
      <dc:creator>sarwshai</dc:creator>
      <dc:date>2020-03-24T14:52:41Z</dc:date>
    </item>
  </channel>
</rss>

