Deployment Architecture

Setup Index limit on daily basis

anirudhk
Explorer

Hi,

Is there any way to setup a limit on index on a daily basis. We have a few projects and associated index for each project and would like to restrict the index intake based on the projects/index.

Thanks
Anirudh

Tags (1)
0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You could set up a license master with a pool, putting the indexers which index data for project x into pool x. This would mean a license violation is incurred for the pool which sends more data than is allowed. As lukejadamec points out, you don't want to stop indexing data because that's really just kicking the can down the road. Once you start indexing data again, you're going to index all of that data you'd missed until that point and the current data.

lukejadamec
Super Champion

No. I've never seen a setting that tell Splunk to stop indexing data based on volume. This is probably because of the way Splunk monitors logs: If Splunk were to stop indexing at some time during the day, the logs would continue to populate regardless, so on the next day Splunk would just start where it left off.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...