Archive

How to properly disable an index to avoid any potential impact?

Explorer

Hi , currently i have an index which receives data from more then 100 hosts. I have been told to disable the index , as we are in cluster i edit the indexes.conf file and added disabled=true , is it going to disable the index ? Also do i need to disable the monitoring path currently forwarded to this index ? I am confuse can any one please explain the proper steps that needs to follow to disable an index to avoid any potential impact ?

0 Karma
1 Solution

SplunkTrust
SplunkTrust

Hi,

I would start by disabling the corresponding inputs.conf specification first. When you're sure no new data is coming in, you can, as you said, simply add disabled = true to the indexes.conf index' stanza.

Skalli

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

Hi,

I would start by disabling the corresponding inputs.conf specification first. When you're sure no new data is coming in, you can, as you said, simply add disabled = true to the indexes.conf index' stanza.

Skalli

View solution in original post

0 Karma

Explorer

Thanks it works.

0 Karma

SplunkTrust
SplunkTrust

Glad it worked, thanks for the feedback!

0 Karma