Deployment Architecture

why my indexes are filling up quickly

MAMAOUI
Explorer

Hello
I have an index(es) that are beginning to rapidly fill up,how can i determine the reason and solve it?!
Thanks
M&A

0 Karma
1 Solution

FrankVl
Ultra Champion

Take a look at your data and see which source / host is spiking and then investigate why that source / host is spiking and decide whether there is something wrong with that source / host that needs to be fixed, or whether this event volume is to be expected (and then adjust Splunk to scale to that demand).

View solution in original post

0 Karma

FrankVl
Ultra Champion

Take a look at your data and see which source / host is spiking and then investigate why that source / host is spiking and decide whether there is something wrong with that source / host that needs to be fixed, or whether this event volume is to be expected (and then adjust Splunk to scale to that demand).

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...