<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: hot_v* file not found but able to see file using locate in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/hot-v-file-not-found-but-able-to-see-file-using-locate/m-p/317959#M165530</link>
    <description>&lt;P&gt;The digits at the end of the hot bucket directories are sequential numbers. Hot buckets are rolled to warm (db_*) based on index configuration parameters, or when you stop/restart splunk. So those hot bucket names change all the time as new data comes in.&lt;BR /&gt;
defaultdb is (by default) mapped to the 'main' index. If you don't ingest any data here, you won't have hot buckets.&lt;BR /&gt;
I would recommend you use the &lt;A href="https://splunk-sizing.appspot.com/"&gt;Splunk Sizing Tool&lt;/A&gt; to figure out what your storage requirements are.&lt;BR /&gt;
Select your daily data volume, retention settings, etc. and it will give you an estimate on per-indexer and total data storage needs for HOT/WARM and COLD volumes.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2017 07:22:24 GMT</pubDate>
    <dc:creator>s2_splunk</dc:creator>
    <dc:date>2017-10-19T07:22:24Z</dc:date>
    <item>
      <title>hot_v* file not found but able to see file using locate</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hot-v-file-not-found-but-able-to-see-file-using-locate/m-p/317958#M165529</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Referencing to &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Capacity/Estimateyourstoragerequirements" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Capacity/Estimateyourstoragerequirements&lt;/A&gt;, &lt;BR /&gt;
I'm trying to estimate my storage space on Linux. At /opt/splunk/var/lib/splunk/defaultdb, when I run "du -ch hot_v*", terminal says no such file or directory. &lt;/P&gt;

&lt;P&gt;I did a locate hot_v and a list below came up and one of them in the db folder is hot_v1_12. &lt;BR /&gt;
I then did a ls -a and I can't find hot_v1_12. &lt;/P&gt;

&lt;P&gt;Anyone encounter this issue before?&lt;/P&gt;

&lt;P&gt;&lt;IMG src="https://community.splunk.com/storage/temp/217902-capture.jpg" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:20:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hot-v-file-not-found-but-able-to-see-file-using-locate/m-p/317958#M165529</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2020-09-29T16:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: hot_v* file not found but able to see file using locate</title>
      <link>https://community.splunk.com/t5/Splunk-Search/hot-v-file-not-found-but-able-to-see-file-using-locate/m-p/317959#M165530</link>
      <description>&lt;P&gt;The digits at the end of the hot bucket directories are sequential numbers. Hot buckets are rolled to warm (db_*) based on index configuration parameters, or when you stop/restart splunk. So those hot bucket names change all the time as new data comes in.&lt;BR /&gt;
defaultdb is (by default) mapped to the 'main' index. If you don't ingest any data here, you won't have hot buckets.&lt;BR /&gt;
I would recommend you use the &lt;A href="https://splunk-sizing.appspot.com/"&gt;Splunk Sizing Tool&lt;/A&gt; to figure out what your storage requirements are.&lt;BR /&gt;
Select your daily data volume, retention settings, etc. and it will give you an estimate on per-indexer and total data storage needs for HOT/WARM and COLD volumes.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 07:22:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/hot-v-file-not-found-but-able-to-see-file-using-locate/m-p/317959#M165530</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-19T07:22:24Z</dc:date>
    </item>
  </channel>
</rss>

