<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I get SmartStore to fill its cache again? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-get-SmartStore-to-fill-its-cache-again/m-p/574126#M200083</link>
    <description>&lt;P&gt;We have Splunk 8.0.3 deployed to a private AWS cloud.&lt;/P&gt;&lt;P&gt;We use AWS i3.8xlarge instance types for our indexers, recently upgraded from i3.4xlarge.&lt;/P&gt;&lt;P&gt;We combine the 1.7TB "ephemeral" volumes into a logical volume group and use them for splunk index buckets mounted on /opt/splunk/var/lib/splunk.&lt;/P&gt;&lt;P&gt;When we were running on i3.4xlarge instances where we had two 1.7 TB volumes, we were using 3 TB of the 3.4 TB logical volume group per indexer as Splunk&amp;nbsp; indexes.&lt;/P&gt;&lt;P&gt;When we upgraded to i3.8xlarges we removed the old indexers and the new indexers are only using 200GB of the 6.8TB logical volume groups, slowly creeping up about 4GB/hour.&lt;/P&gt;&lt;P&gt;I have tried running searches over long periods of time, but they fail with:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;! DAG Execution Exception: Search has been cancelled&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;! Search auto-canceled&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;! The search job has failed due to an error.&amp;nbsp; You may be able view the job in the Job Inspector&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;How do I get the cache volumes to fill up again quickly with index data from the S3 storage so my searches will be fast and complete again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Nov 2021 05:28:19 GMT</pubDate>
    <dc:creator>esalesap</dc:creator>
    <dc:date>2021-11-09T05:28:19Z</dc:date>
    <item>
      <title>How do I get SmartStore to fill its cache again?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-get-SmartStore-to-fill-its-cache-again/m-p/574126#M200083</link>
      <description>&lt;P&gt;We have Splunk 8.0.3 deployed to a private AWS cloud.&lt;/P&gt;&lt;P&gt;We use AWS i3.8xlarge instance types for our indexers, recently upgraded from i3.4xlarge.&lt;/P&gt;&lt;P&gt;We combine the 1.7TB "ephemeral" volumes into a logical volume group and use them for splunk index buckets mounted on /opt/splunk/var/lib/splunk.&lt;/P&gt;&lt;P&gt;When we were running on i3.4xlarge instances where we had two 1.7 TB volumes, we were using 3 TB of the 3.4 TB logical volume group per indexer as Splunk&amp;nbsp; indexes.&lt;/P&gt;&lt;P&gt;When we upgraded to i3.8xlarges we removed the old indexers and the new indexers are only using 200GB of the 6.8TB logical volume groups, slowly creeping up about 4GB/hour.&lt;/P&gt;&lt;P&gt;I have tried running searches over long periods of time, but they fail with:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;! DAG Execution Exception: Search has been cancelled&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;! Search auto-canceled&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;! The search job has failed due to an error.&amp;nbsp; You may be able view the job in the Job Inspector&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;How do I get the cache volumes to fill up again quickly with index data from the S3 storage so my searches will be fast and complete again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 05:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-get-SmartStore-to-fill-its-cache-again/m-p/574126#M200083</guid>
      <dc:creator>esalesap</dc:creator>
      <dc:date>2021-11-09T05:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: How do I get SmartStore to fill its cache again?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-get-SmartStore-to-fill-its-cache-again/m-p/574494#M200210</link>
      <description>&lt;P class="lia-align-justify"&gt;Ok, so the "DAG Execution" errors were caused by me running long-running searches in multiple browser tabs.&amp;nbsp; The errors would occur if I switched between tabs.&amp;nbsp; Running searches in their own windows solved the search error problem.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;I'm still looking for a fast way to stimulate the indexers to load previously indexed data from S3 to the indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 20:36:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-get-SmartStore-to-fill-its-cache-again/m-p/574494#M200210</guid>
      <dc:creator>esalesap</dc:creator>
      <dc:date>2021-11-10T20:36:23Z</dc:date>
    </item>
  </channel>
</rss>

