Deployment Architecture

Cap daily indexation of an index

internet_team
Explorer

Hello,

We currently have an index that has a size ranging from 3 to 7 Go per day, is there any way to limit the daily indexation to, lets say, 5 Go ?

Expected behaviour is : when the index size hits 5Go, it stops indexing new data to avoid license usage.

We already tried the thruput limitation in a limits.conf file and it does not work well enough for us. We'd also prefer not to have a Splunk alert launch a script on our servers.

Thanks in advance !

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

internet_team
Explorer

Hello, thanks for the quick answer.

Is this going to be implemented in the near future ?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Not in the near to distant future. If you talk to you account rep, ask them to file an ERD and request this. That can help!!

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...