Deployment Architecture

How to change the index size of _audit index on a cluster?

agentguerry
Path Finder

I have a cluster set up with 1 index master, and 2 index peers.

I would like to change the size of the _audit index from 500G to 400G.

How can I go about changing these? On my index master, in the inputs.conf file that gets pushed out, there is no _audit index since these are created from splunk setup. I cannot go to each peer and change them manually, b/c the peers are part of a cluster.

Thanks!

0 Karma

mayurr98
Super Champion

On both indexers, you would need to create a stanza.
go to $SPLUNK_HOME/etc/system/local/indexes.conf

and create

[_audit]

0 Karma

agentguerry
Path Finder

would doing that clobber the existing data/index that is on the peer servers?

0 Karma

mayurr98
Super Champion

no it won't

0 Karma

mayurr98
Super Champion
0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...