Getting Data In
Highlighted

How to check if indexer is writing cold to frozen?

Builder

I have an ec2 splunk instance writing frozen data to an s3 bucket (via s3fs).

Where would I find in the splunk logs a history to monitor: when data is written to, and how much data is written to the frozen dir?

Thank you

Tags (2)
0 Karma
Highlighted

Re: How to check if indexer is writing cold to frozen?

Contributor

try this and see if its what you're looking for

index=_internal source=*splunkd.log  Reason="' frozen_buckets'"

View solution in original post

0 Karma
Highlighted

Re: How to check if indexer is writing cold to frozen?

Builder

index = internal is correct. fyi, when looking for s3fs events I have to search for the s3fs mount point like
the following (where foo is the s3fs mount point).
index=
internal source="/opt/splunk/var/log/splunk/splunkd.log" "/foo/frozenarchive/someindexofinterest"

0 Karma