Archive

How does splunk prune block signatures?

Engager

Hi all,

We have enabled data block signing as described in http://docs.splunk.com/Documentation/Splunk/latest/admin/ITDataSigning

However the _blocksignature index is growing very large. For 3 months of data it's already at 200GB. It also has some events older than our main index.

Is it possible to let splunk delete from this index when the relevant source data in the main index is purged?

What can we do to limit the disk usage by the block signatures? Preferably we would like to be able to validate data from a year ago, but that may be unrealistic based on these space requirements.

Tags (1)
0 Karma

Splunk Employee
Splunk Employee

You can set the retention for that index the same as any other index.

Splunk Employee
Splunk Employee

I'd suggest filing a support case for an enhancement request for this.

0 Karma

Engager

Thanks. So there's no way to link the retention so that block signatures are deleted when the relevant data in the main index is rolled to frozen?

0 Karma