Deployment Architecture

I've read it's not recommended to build indexes with maxdatasize for buckets less than 750mb, but what about indexes that do not generate many events?

xxyz
Explorer

I've read that it's not recommended to build indexes with maxdatasize for buckets less than 750mb. What about for small footprint indexes that do not generate a lot of events?

Tags (3)
0 Karma

hortonew
Builder

Perfectly acceptable to lower this. Splunk provides an example of this on their indexes.conf page:

http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/Indexesconf
maxDataSize = 500

The recommendations depend on your bucket rotation strategies (how many warm buckets you're keeping, where they're going afterwards, etc).

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...