Deployment Architecture

I've read it's not recommended to build indexes with maxdatasize for buckets less than 750mb, but what about indexes that do not generate many events?

xxyz
Explorer

I've read that it's not recommended to build indexes with maxdatasize for buckets less than 750mb. What about for small footprint indexes that do not generate a lot of events?

Tags (3)
0 Karma

hortonew
Builder

Perfectly acceptable to lower this. Splunk provides an example of this on their indexes.conf page:

http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/Indexesconf
maxDataSize = 500

The recommendations depend on your bucket rotation strategies (how many warm buckets you're keeping, where they're going afterwards, etc).

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...