Deployment Architecture

How to change the index size of _audit index on a cluster?

agentguerry
Path Finder

I have a cluster set up with 1 index master, and 2 index peers.

I would like to change the size of the _audit index from 500G to 400G.

How can I go about changing these? On my index master, in the inputs.conf file that gets pushed out, there is no _audit index since these are created from splunk setup. I cannot go to each peer and change them manually, b/c the peers are part of a cluster.

Thanks!

0 Karma

mayurr98
Super Champion

On both indexers, you would need to create a stanza.
go to $SPLUNK_HOME/etc/system/local/indexes.conf

and create

[_audit]

0 Karma

agentguerry
Path Finder

would doing that clobber the existing data/index that is on the peer servers?

0 Karma

mayurr98
Super Champion

no it won't

0 Karma

mayurr98
Super Champion
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...