Deployment Architecture

I've read it's not recommended to build indexes with maxdatasize for buckets less than 750mb, but what about indexes that do not generate many events?

xxyz
Explorer

I've read that it's not recommended to build indexes with maxdatasize for buckets less than 750mb. What about for small footprint indexes that do not generate a lot of events?

Tags (3)
0 Karma

hortonew
Builder

Perfectly acceptable to lower this. Splunk provides an example of this on their indexes.conf page:

http://docs.splunk.com/Documentation/Splunk/6.2.4/admin/Indexesconf
maxDataSize = 500

The recommendations depend on your bucket rotation strategies (how many warm buckets you're keeping, where they're going afterwards, etc).

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...