Getting Data In

Reducing maxWarmDBCount below current warm bucket count.

mgherman
Explorer

Hi,

To utilise some additional space that I have brought online, I have configured the colddb path to use new storage and new warm-to-cold migrations are using the new storage.

Currently the maxWarmDBCount is set to the default (300) in the $SPLUNK_HOME/etc/system/default/indexes.conf, if I add a maxWarmDBCount setting to $SPLUNK_HOME/etc/system/local/indexes.conf at a value less than the number of warm buckets that currently exist, will splunk "do the right thing" and migrate the oldest warm buckets to the cold storage until it gets to the new maxWarmDBCount value?

Thanks again,

mgh

Tags (2)
1 Solution

dwaddle
SplunkTrust
SplunkTrust

Yes, once you restart splunkd and give it a little time to do so. It may not do it immediately upon restart, but it will notice there are currently more warm buckets than there are set to be, and it will roll the oldest ones to cold until it matches your policy.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

Yes, once you restart splunkd and give it a little time to do so. It may not do it immediately upon restart, but it will notice there are currently more warm buckets than there are set to be, and it will roll the oldest ones to cold until it matches your policy.

mgherman
Explorer

As if by magic. Thanks again.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...