Getting Data In

Disable index

sidekix24
Path Finder

We'd like to disable indexing to a certain index temporarily but we don't have access to the forwarder. Will simply disabling the index in the Splunk UI do the trick? It shouldn't delete our data or cause any other issues, correct?

Please let me know if anyone has any suggestions

Thanks

0 Karma

woodcock
Esteemed Legend

If you disable the index then 1 of 2 things will happen. Either the data will end up in your lastChanceIndex (most people do not define this) or it will temporarily back up on the forwarder and the forwarder will begin to consume a large amount of RAM and disk space and this will grow for the duration of the outage; this can cause significant problems on the forwarder for the REAL work that is supposed to happen there. When the index comes back online, all the backlogged data will come flooding in to the indexers which can overwhelm the indexers and also cause license violations (think 5 days of data coming to the indexers in just an hour) which will also cause a huge CPU spike on the forwarder. I would not go this route.

I would either:

Configure a lastChanceIndex and then kill the existing index.
https://docs.splunk.com/Documentation/Splunk/6.5.3/Admin/Indexesconf

Configure a nullRoute on the Indexer to divert this data from the current destination to a trash can:
http://docs.splunk.com/Documentation/Splunk/6.5.3/Forwarding/Routeandfilterdatad#Filter_event_data_a...

somesoni2
Revered Legend

From Documentation link

Unlike the remove index command, disable index does not delete index data, and it is reversible (with the enable index command). However, once an index is disabled, splunkd will no longer accept data targeted at it.

http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/RemovedatafromSplunk#Disable_an_index_with...

How have you configured data monitoring on forwarders, using deployment server to push apps OR directly updating configs on them? The reason I asked is that best method would to get all those data input configs disabled so that forwarder won't monitor and send data for that index, save precious resources on forwarder/indexer.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...