Hi all,
On one of my environments, I ran out of space on the weekend. As it's not my primary production environment, generally I don't want to micro-manage indexes or retention as we do with production. I don't really care how long data is retained for, but I want to retain it for as long as possible before space limits hit.
In this case, if I have the following settings, why will it go 10-15 GB over the hot limit, even following a rolling restart of the indexer cluster?
[volume:hot1]
path = /splunkdata/hot
maxVolumeDataSizeMB = 70000
[volume:cold1]
path = /splunkdata/cold
maxVolumeDataSizeMB = 30000
What are the settings you have for your indexes?
In this case I don't want to manage the settings for my indexers individually. This is a test environment where I want an absolute max size and not to worry about retention for individual indexes, while still keeping as much data as possible.