Deployment Architecture

Cap daily indexation of an index

internet_team
Explorer

Hello,

We currently have an index that has a size ranging from 3 to 7 Go per day, is there any way to limit the daily indexation to, lets say, 5 Go ?

Expected behaviour is : when the index size hits 5Go, it stops indexing new data to avoid license usage.

We already tried the thruput limitation in a limits.conf file and it does not work well enough for us. We'd also prefer not to have a Splunk alert launch a script on our servers.

Thanks in advance !

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

internet_team
Explorer

Hello, thanks for the quick answer.

Is this going to be implemented in the near future ?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Not in the near to distant future. If you talk to you account rep, ask them to file an ERD and request this. That can help!!

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...