Deployment Architecture

How does frozenTimePeriodInSecs and maxWarmDBCount perform

rickymckenzie10
Explorer

Currently, each of my indexes is set to a specific and own frozenTimePeriodInSecs, but I am noticing they are not rolling over to cold when the frozenTimePeriodInSecs value is set.

Data Age (keeps growing) vs Frozen Age (stays as what it is set in frozenTimePeriodInSecs)

maxWarmDBCount is set to:

 

maxWarmDBCount = 4294967295

 

 Does this effect?

If the value is changed, would data roll to cold?

Labels (2)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@rickymckenzie10 - To simplify your understanding of warm and cold buckets and different parameters.

(Only applicable when you are not using volumes)

 

Warm Buckets -> buckets in /db path

Cold Buckets -> buckets in /colddb path

Frozen Buckets -> Deleted/Archived data

 

Warm to Cold Bucket Movement -> when maxWarmDBCount bucket count is reached.

 

Cold to Frozen (deleting, max age) Bucket Movement -> when all events are older than frozenTimePeriodInSecs

 

I hope this helps you understand the parameters better. Kindly upvote if it does!!!

0 Karma

victor_menezes
Path Finder

Hey Ricky,

AFAIK maxWarmDBCount doesn't affect the rollover of data (but it can be storage hungry so be careful with that), it is something the frozenTimePeriodInSecs do instead. In your case, if I understood correctly, the frozen time already passed but your data did not rolled over, and that may be either because your cluster manager is too busy at the moment (and you are experiencing delay in this processing) OR maybe it is waiting for the buckets to hit a threshold in size. Check the bucket replication status also, it may indicate if there is any problem in there...

Are you using maxTotalDataSizeMB key by any chance? Try to add that also to see if you get any diff behavior.

0 Karma

rickymckenzie10
Explorer

@victor_menezes can you expand a little more on this:

AFAIK maxWarmDBCount doesn't affect the rollover of data (but it can be storage hungry so be careful with that), it is something the frozenTimePeriodInSecs do instead

Yes, I am using maxTotalDataSizeMB in each of the indexes. They all have their specific size.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...