Archive
Highlighted

why my indexes are filling up quickly

Explorer

Hello
I have an index(es) that are beginning to rapidly fill up,how can i determine the reason and solve it?!
Thanks
M&A

0 Karma
Highlighted

Re: why my indexes are filling up quickly

Ultra Champion

Take a look at your data and see which source / host is spiking and then investigate why that source / host is spiking and decide whether there is something wrong with that source / host that needs to be fixed, or whether this event volume is to be expected (and then adjust Splunk to scale to that demand).

View solution in original post

0 Karma