We currently have an index that has a size ranging from 3 to 7 Go per day, is there any way to limit the daily indexation to, lets say, 5 Go ?
Expected behaviour is : when the index size hits 5Go, it stops indexing new data to avoid license usage.
We already tried the thruput limitation in a limits.conf file and it does not work well enough for us. We'd also prefer not to have a Splunk alert launch a script on our servers.
Thanks in advance !