Deployment Architecture

Cap daily indexation of an index

internet_team
Explorer

Hello,

We currently have an index that has a size ranging from 3 to 7 Go per day, is there any way to limit the daily indexation to, lets say, 5 Go ?

Expected behaviour is : when the index size hits 5Go, it stops indexing new data to avoid license usage.

We already tried the thruput limitation in a limits.conf file and it does not work well enough for us. We'd also prefer not to have a Splunk alert launch a script on our servers.

Thanks in advance !

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

internet_team
Explorer

Hello, thanks for the quick answer.

Is this going to be implemented in the near future ?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Not in the near to distant future. If you talk to you account rep, ask them to file an ERD and request this. That can help!!

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...