<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Updated indexes.conf and now there is no data for old days data from splunk search result? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Updated-indexes-conf-and-now-there-is-no-data-for-old-days-data/m-p/646335#M223717</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have updated the indexes.conf file&amp;nbsp;homePath.maxDataSizeMB&amp;nbsp; from 13gb to 30gb &amp;amp; maxTotalDataSizeMB 13gb to 30gb.And after that from search result i am not able to see old days data.Can anyone provide information how to check and fix this by getting old data in splunk?&lt;/P&gt;
&lt;P&gt;indexes.conf file values now:&lt;/P&gt;
&lt;P&gt;#aws_riskinfo&lt;BR /&gt;[aws_riskinfo]&lt;BR /&gt;homePath = volume:hotwarm/aws_riskinfo/db&lt;BR /&gt;coldPath = volume:hotwarm/aws_riskinfo/colddb&lt;BR /&gt;thawedPath = /prod/appli_is/splunk_indexes/archives/ARCH1Y/aws_riskinfo/thaweddb&lt;BR /&gt;homePath.maxDataSizeMB = 30000&lt;BR /&gt;coldPath.maxDataSizeMB = 0&lt;BR /&gt;maxTotalDataSizeMB = 30000&lt;BR /&gt;maxWarmDBCount = 4294967295&lt;BR /&gt;frozenTimePeriodInSecs = 7776000&lt;BR /&gt;#maxDataSize = auto_high_volume&lt;BR /&gt;coldToFrozenDir = /prod/appli_is/splunk_indexes/archives/ARCH1Y/aws_riskinfo/frozen&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jun 2023 14:41:25 GMT</pubDate>
    <dc:creator>ashiq1993</dc:creator>
    <dc:date>2023-06-08T14:41:25Z</dc:date>
    <item>
      <title>Updated indexes.conf and now there is no data for old days data from splunk search result?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Updated-indexes-conf-and-now-there-is-no-data-for-old-days-data/m-p/646335#M223717</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have updated the indexes.conf file&amp;nbsp;homePath.maxDataSizeMB&amp;nbsp; from 13gb to 30gb &amp;amp; maxTotalDataSizeMB 13gb to 30gb.And after that from search result i am not able to see old days data.Can anyone provide information how to check and fix this by getting old data in splunk?&lt;/P&gt;
&lt;P&gt;indexes.conf file values now:&lt;/P&gt;
&lt;P&gt;#aws_riskinfo&lt;BR /&gt;[aws_riskinfo]&lt;BR /&gt;homePath = volume:hotwarm/aws_riskinfo/db&lt;BR /&gt;coldPath = volume:hotwarm/aws_riskinfo/colddb&lt;BR /&gt;thawedPath = /prod/appli_is/splunk_indexes/archives/ARCH1Y/aws_riskinfo/thaweddb&lt;BR /&gt;homePath.maxDataSizeMB = 30000&lt;BR /&gt;coldPath.maxDataSizeMB = 0&lt;BR /&gt;maxTotalDataSizeMB = 30000&lt;BR /&gt;maxWarmDBCount = 4294967295&lt;BR /&gt;frozenTimePeriodInSecs = 7776000&lt;BR /&gt;#maxDataSize = auto_high_volume&lt;BR /&gt;coldToFrozenDir = /prod/appli_is/splunk_indexes/archives/ARCH1Y/aws_riskinfo/frozen&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 14:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Updated-indexes-conf-and-now-there-is-no-data-for-old-days-data/m-p/646335#M223717</guid>
      <dc:creator>ashiq1993</dc:creator>
      <dc:date>2023-06-08T14:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Updated indexes.conf and now there is no data for old days data from splunk search result?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Updated-indexes-conf-and-now-there-is-no-data-for-old-days-data/m-p/646439#M223748</link>
      <description>&lt;P&gt;Any knowledge available to fix this case?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 11:51:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Updated-indexes-conf-and-now-there-is-no-data-for-old-days-data/m-p/646439#M223748</guid>
      <dc:creator>ashiq1993</dc:creator>
      <dc:date>2023-06-09T11:51:46Z</dc:date>
    </item>
  </channel>
</rss>

