Deployment Architecture

If a cold to frozen script fails, what happens?

roychen
Path Finder

Hello,

In indexes.conf, we can specify a value for coldToFrozenScript, to run a specific script when cold buckets are rolled to frozen.

What happens if the script fails to execute, or returns an error code, etc, when a rolling of cold buckets to frozen is triggered?

Will the cold buckets be deleted in this case?

Thanks!

Tags (1)
0 Karma
1 Solution

roychen
Path Finder

According to Splunk support, if the script to roll cold buckets to frozen fails to run, the cold buckets will not be deleted.

If these cold buckets are not deleted, and new incoming data would cause the index to exceed its configured size, Splunk will not delete the cold buckets to make room. Instead, the index will grow in size till the script is fixed.

View solution in original post

roychen
Path Finder

According to Splunk support, if the script to roll cold buckets to frozen fails to run, the cold buckets will not be deleted.

If these cold buckets are not deleted, and new incoming data would cause the index to exceed its configured size, Splunk will not delete the cold buckets to make room. Instead, the index will grow in size till the script is fixed.

the_wolverine
Champion

You can configure deletion by age AND by size. The condition that matches first will prevail. It is possible that the second condition will never match due to the first condition.

0 Karma

chimbudp
Contributor

If we had set the limit of index to a particular smaller value (say 100MB),Will Splunk overrides the value to auto and make the index size to grow ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...