Deployment Architecture

Setup Index limit on daily basis

anirudhk
Explorer

Hi,

Is there any way to setup a limit on index on a daily basis. We have a few projects and associated index for each project and would like to restrict the index intake based on the projects/index.

Thanks
Anirudh

Tags (1)
0 Karma

jbsplunk
Splunk Employee
Splunk Employee

You could set up a license master with a pool, putting the indexers which index data for project x into pool x. This would mean a license violation is incurred for the pool which sends more data than is allowed. As lukejadamec points out, you don't want to stop indexing data because that's really just kicking the can down the road. Once you start indexing data again, you're going to index all of that data you'd missed until that point and the current data.

lukejadamec
Super Champion

No. I've never seen a setting that tell Splunk to stop indexing data based on volume. This is probably because of the way Splunk monitors logs: If Splunk were to stop indexing at some time during the day, the logs would continue to populate regardless, so on the next day Splunk would just start where it left off.

Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...