Monitoring Splunk

How to properly disable an index to avoid any potential impact?

ram254481493
Explorer

Hi , currently i have an index which receives data from more then 100 hosts. I have been told to disable the index , as we are in cluster i edit the indexes.conf file and added disabled=true , is it going to disable the index ? Also do i need to disable the monitoring path currently forwarded to this index ? I am confuse can any one please explain the proper steps that needs to follow to disable an index to avoid any potential impact ?

0 Karma
1 Solution

skalliger
Motivator

Hi,

I would start by disabling the corresponding inputs.conf specification first. When you're sure no new data is coming in, you can, as you said, simply add disabled = true to the indexes.conf index' stanza.

Skalli

View solution in original post

0 Karma

skalliger
Motivator

Hi,

I would start by disabling the corresponding inputs.conf specification first. When you're sure no new data is coming in, you can, as you said, simply add disabled = true to the indexes.conf index' stanza.

Skalli

0 Karma

ram254481493
Explorer

Thanks it works.

0 Karma

skalliger
Motivator

Glad it worked, thanks for the feedback!

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...