On one of my environments, I ran out of space on the weekend. As it's not my primary production environment, generally I don't want to micro-manage indexes or retention as we do with production. I don't really care how long data is retained for, but I want to retain it for as long as possible before space limits hit.
In this case, if I have the following settings, why will it go 10-15 GB over the hot limit, even following a rolling restart of the indexer cluster?
[volume:hot1] path = /splunkdata/hot maxVolumeDataSizeMB = 70000 [volume:cold1] path = /splunkdata/cold maxVolumeDataSizeMB = 30000
In this case I don't want to manage the settings for my indexers individually. This is a test environment where I want an absolute max size and not to worry about retention for individual indexes, while still keeping as much data as possible.