Monitoring Splunk

How to properly disable an index to avoid any potential impact?

ram254481493
Explorer

Hi , currently i have an index which receives data from more then 100 hosts. I have been told to disable the index , as we are in cluster i edit the indexes.conf file and added disabled=true , is it going to disable the index ? Also do i need to disable the monitoring path currently forwarded to this index ? I am confuse can any one please explain the proper steps that needs to follow to disable an index to avoid any potential impact ?

0 Karma
1 Solution

skalliger
SplunkTrust
SplunkTrust

Hi,

I would start by disabling the corresponding inputs.conf specification first. When you're sure no new data is coming in, you can, as you said, simply add disabled = true to the indexes.conf index' stanza.

Skalli

View solution in original post

0 Karma

skalliger
SplunkTrust
SplunkTrust

Hi,

I would start by disabling the corresponding inputs.conf specification first. When you're sure no new data is coming in, you can, as you said, simply add disabled = true to the indexes.conf index' stanza.

Skalli

0 Karma

ram254481493
Explorer

Thanks it works.

0 Karma

skalliger
SplunkTrust
SplunkTrust

Glad it worked, thanks for the feedback!

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...