Getting Data In

Can we limit disk usage at the default stanza of indexes.conf?

ddrillic
Ultra Champion

Is it possible to set maxTotalDataSizeMB to let's say 6 TBs in the default stanza?

We are at 98% disk utilization ; -)

Tags (1)
0 Karma
1 Solution

damann
Communicator

so maxVolumeDataSizeMB should be the option you are looking for.
Did you already took a look in the docs for maxTotalDataSizeMB, maxGlobalDataSizeMB and maxVolumeDataSizeMB ?

Quote from indexes.conf docs:
maxVolumeDataSizeMB: If set, this attribute limits the total size of all databases that reside
on this volume to the maximum size specified, in MB. Note that this it
will act only on those indexes which reference this volume, not on the
total size of the path set in the path attribute of this volume.

View solution in original post

0 Karma

damann
Communicator

so maxVolumeDataSizeMB should be the option you are looking for.
Did you already took a look in the docs for maxTotalDataSizeMB, maxGlobalDataSizeMB and maxVolumeDataSizeMB ?

Quote from indexes.conf docs:
maxVolumeDataSizeMB: If set, this attribute limits the total size of all databases that reside
on this volume to the maximum size specified, in MB. Note that this it
will act only on those indexes which reference this volume, not on the
total size of the path set in the path attribute of this volume.

0 Karma

ddrillic
Ultra Champion

Gorgeous!!

0 Karma

ddrillic
Ultra Champion

Apparently without defining the volume we can't use this maxVolumeDataSizeMB configuration.

0 Karma

damann
Communicator

Sure. have a look in the docs for indexes.conf : https://docs.splunk.com/Documentation/Splunk/7.2.1/Admin/Indexesconf

maxVolumeDataSizeMB = positive integer

should be the right option for you

0 Karma

ddrillic
Ultra Champion

Right, can we do it in the default stanza?

0 Karma

damann
Communicator

sure, everything you define in the default stanza will be applied globally on all your indexes

0 Karma

ddrillic
Ultra Champion

Oh, but we need to limit the total usage of all the indexes...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...