Deployment Architecture

Cap daily indexation of an index

internet_team
Explorer

Hello,

We currently have an index that has a size ranging from 3 to 7 Go per day, is there any way to limit the daily indexation to, lets say, 5 Go ?

Expected behaviour is : when the index size hits 5Go, it stops indexing new data to avoid license usage.

We already tried the thruput limitation in a limits.conf file and it does not work well enough for us. We'd also prefer not to have a Splunk alert launch a script on our servers.

Thanks in advance !

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

internet_team
Explorer

Hello, thanks for the quick answer.

Is this going to be implemented in the near future ?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Not in the near to distant future. If you talk to you account rep, ask them to file an ERD and request this. That can help!!

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...