<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SmartStore Cache Policy to Preserve Recent Buckets while searching from S3 Object Store in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SmartStore-Cache-Policy-to-Preserve-Recent-Buckets-while/m-p/502759#M8897</link>
    <description>&lt;P&gt;I want to balance the use of cache capacity with SmartStore. I want to keep recent buckets in cache while allowing older buckets to be expired so I can search with the S3 object store.&lt;/P&gt;

&lt;P&gt;Based on what I read in...&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/ConfigureSmartStorecachemanager" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/ConfigureSmartStorecachemanager&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I believe setting "hotlist_recency_secs" and "hotlist_bloom_filter_recency_hours" would allow me to accomplish what I seek. i.e. protect buckets processed within the last 7 days and use remaining cache capacity for buckets retrieved from S3.&lt;/P&gt;

&lt;P&gt;Can someone confirm my logic or point me in the right direction?&lt;/P&gt;

&lt;P&gt;thx&lt;BR /&gt;
-v&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:45:34 GMT</pubDate>
    <dc:creator>stewdapew</dc:creator>
    <dc:date>2020-09-30T04:45:34Z</dc:date>
    <item>
      <title>SmartStore Cache Policy to Preserve Recent Buckets while searching from S3 Object Store</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/SmartStore-Cache-Policy-to-Preserve-Recent-Buckets-while/m-p/502759#M8897</link>
      <description>&lt;P&gt;I want to balance the use of cache capacity with SmartStore. I want to keep recent buckets in cache while allowing older buckets to be expired so I can search with the S3 object store.&lt;/P&gt;

&lt;P&gt;Based on what I read in...&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/ConfigureSmartStorecachemanager" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/ConfigureSmartStorecachemanager&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I believe setting "hotlist_recency_secs" and "hotlist_bloom_filter_recency_hours" would allow me to accomplish what I seek. i.e. protect buckets processed within the last 7 days and use remaining cache capacity for buckets retrieved from S3.&lt;/P&gt;

&lt;P&gt;Can someone confirm my logic or point me in the right direction?&lt;/P&gt;

&lt;P&gt;thx&lt;BR /&gt;
-v&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:45:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/SmartStore-Cache-Policy-to-Preserve-Recent-Buckets-while/m-p/502759#M8897</guid>
      <dc:creator>stewdapew</dc:creator>
      <dc:date>2020-09-30T04:45:34Z</dc:date>
    </item>
  </channel>
</rss>

