Deployment Architecture

How to change the index size of _audit index on a cluster?

agentguerry
Path Finder

I have a cluster set up with 1 index master, and 2 index peers.

I would like to change the size of the _audit index from 500G to 400G.

How can I go about changing these? On my index master, in the inputs.conf file that gets pushed out, there is no _audit index since these are created from splunk setup. I cannot go to each peer and change them manually, b/c the peers are part of a cluster.

Thanks!

0 Karma

mayurr98
Super Champion

On both indexers, you would need to create a stanza.
go to $SPLUNK_HOME/etc/system/local/indexes.conf

and create

[_audit]

0 Karma

agentguerry
Path Finder

would doing that clobber the existing data/index that is on the peer servers?

0 Karma

mayurr98
Super Champion

no it won't

0 Karma

mayurr98
Super Champion
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...