Getting Data In

What will happen when an index reaches its maximum size?

calvintkng
New Member

Just would like to know what will happen when an index reaches its maximum size? Will old data automatically be purged and continue to index new data?

Tags (2)
0 Karma
1 Solution

HiroshiSatoh
Champion

It becomes Frozen buckets.

Frozen :
Data rolled from cold. The indexer deletes frozen data by default, but you can also archive it. Archived data can later be thawed.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/HowSplunkstoresindexes

View solution in original post

HiroshiSatoh
Champion

It becomes Frozen buckets.

Frozen :
Data rolled from cold. The indexer deletes frozen data by default, but you can also archive it. Archived data can later be thawed.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/HowSplunkstoresindexes

HiroshiSatoh
Champion

If you run out of disk space, the indexer stops indexing.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Setlimitsondiskusage

maxDataSize,maxTotalDataSizeMB,frozenTimePeriodInSecs...etc

Please read the description of indexes.conf for the parameters to be set.

calvintkng
New Member

Thanks. So this mean if I set the maximum size of my index correct, I shouldn't run out of disk space. Right?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...