Deployment Architecture

If a cold to frozen script fails, what happens?

roychen
Path Finder

Hello,

In indexes.conf, we can specify a value for coldToFrozenScript, to run a specific script when cold buckets are rolled to frozen.

What happens if the script fails to execute, or returns an error code, etc, when a rolling of cold buckets to frozen is triggered?

Will the cold buckets be deleted in this case?

Thanks!

Tags (1)
0 Karma
1 Solution

roychen
Path Finder

According to Splunk support, if the script to roll cold buckets to frozen fails to run, the cold buckets will not be deleted.

If these cold buckets are not deleted, and new incoming data would cause the index to exceed its configured size, Splunk will not delete the cold buckets to make room. Instead, the index will grow in size till the script is fixed.

View solution in original post

roychen
Path Finder

According to Splunk support, if the script to roll cold buckets to frozen fails to run, the cold buckets will not be deleted.

If these cold buckets are not deleted, and new incoming data would cause the index to exceed its configured size, Splunk will not delete the cold buckets to make room. Instead, the index will grow in size till the script is fixed.

the_wolverine
Champion

You can configure deletion by age AND by size. The condition that matches first will prevail. It is possible that the second condition will never match due to the first condition.

0 Karma

chimbudp
Contributor

If we had set the limit of index to a particular smaller value (say 100MB),Will Splunk overrides the value to auto and make the index size to grow ?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...