Getting Data In

Indexers running out of space despite config in indexes.conf


Hi all,

On one of my environments, I ran out of space on the weekend. As it's not my primary production environment, generally I don't want to micro-manage indexes or retention as we do with production. I don't really care how long data is retained for, but I want to retain it for as long as possible before space limits hit.

In this case, if I have the following settings, why will it go 10-15 GB over the hot limit, even following a rolling restart of the indexer cluster?

path = /splunkdata/hot
maxVolumeDataSizeMB = 70000

path = /splunkdata/cold
maxVolumeDataSizeMB = 30000
What are the settings you have for your indexes?

In this case I don't want to manage the settings for my indexers individually. This is a test environment where I want an absolute max size and not to worry about retention for individual indexes, while still keeping as much data as possible.

