Deployment Architecture

How to change parameters of index which contains data

Konstantinov
Engager

Hello!
I have index in cluster which has data. And i need to change frozenTimePeriodInSecs and maxTotalDataSizeMB parameters. Can i manually edit it in %Splunk%\etc\master-apps_cluster\local\indexes.conf or i need to do it by another way?

Tags (2)
0 Karma
1 Solution

acharlieh
Influencer

Yes, in your case the first step is to edit the file in $SPLUNK_HOME/etc/master-apps/_cluster/local/indexes.conf manually on the cluster master. Then you need to roll out the configuration bundle to the indexer peers either through the web ui or the CLI on the master node as described: http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Updatepeerconfigurations

Double and triple check those settings are correct before pushing the configuration out since as soon as each peer updates it'll start freezing/deleting data that now qualifies with your new settings if they're accidentally too small.

View solution in original post

acharlieh
Influencer

Yes, in your case the first step is to edit the file in $SPLUNK_HOME/etc/master-apps/_cluster/local/indexes.conf manually on the cluster master. Then you need to roll out the configuration bundle to the indexer peers either through the web ui or the CLI on the master node as described: http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Updatepeerconfigurations

Double and triple check those settings are correct before pushing the configuration out since as soon as each peer updates it'll start freezing/deleting data that now qualifies with your new settings if they're accidentally too small.

stephanefotso
Motivator

I was so far from what Konstantinow asked. I think that is the correct answer.
Thanks again.

SGF
0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...