Deployment Architecture

What factors into how Splunk creates new hot buckets?

jitsinha
Path Finder

Can anybody put some light on the factors based on why Splunk creates new Hot buckets??

Like maxDataSize and maxHotBuckets - these are the two factors responsible for rollover from hot to warm.

Labels (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi jitsinha,

you can find everything in the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/HowSplunkstoresindexes :

Newly indexed data goes into a hot bucket, which is a bucket that's both searchable and actively being written to. After the hot bucket reaches a certain size, it becomes a warm bucket ("rolls to warm"), and a new hot bucket is created. 

and / or in the wiki :

hope this helps ...

cheers, MuS

anwarmian
Communicator

I gave an up point because MuS mentions that hot buckets are both searchable and actively being written to. This a good point. Warm buckets, on the other hand, are searchable but NOT actively written to. Splunk restart also rolls hot to warm.

0 Karma

jitsinha
Path Finder

anyone please??

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...