Getting Data In

When does splunk roll data from warm to cold?

robertosegantin
Path Finder

On my test environement I configured and index like this:

[prove_di_cold]
homePath = /root/splunk_hot/prove_di_cold/db
coldPath = /root/splunk_cold/prove_di_cold/colddb
thawedPath = /root/splunk_cold/prove_di_cold/thaweddb
maxWarmDBCount=1
maxDataSize = 1000
maxHotSpanSecs = 40
frozenTimePeriodInSecs = 100
rotatePeriodInSecs = 60
bucketRebuildMemoryHint = 0
coldToFrozenDir = /root/splunk_frozen/prove_di_cold
compressRawdata = 1
enableDataIntegrityControl = 0
enableOnlineBucketRepair = 1
enableTsidxReduction = 0
minHotIdleSecsBeforeForceRoll = 0
rtRouterQueueSize =
rtRouterThreads =
suspendHotRollByDeleteQuery = 0
syncMeta = 1

But splunk never copy any data from hot/warm path to cold or freeze path

Have you got any other information about it?

Thanks

0 Karma
1 Solution

CarsonZa
Contributor

splunk wont roll the data until the bucket is full. its possible your hot bucket(s) arent full to even roll to warm even if the maxHotSpanSecs = 40 is set.

try setting this maxHotBuckets=x to a lower integer default is 3.

https://docs.splunk.com/Documentation/Splunk/7.1.2/Admin/Indexesconf

View solution in original post

0 Karma

CarsonZa
Contributor

splunk wont roll the data until the bucket is full. its possible your hot bucket(s) arent full to even roll to warm even if the maxHotSpanSecs = 40 is set.

try setting this maxHotBuckets=x to a lower integer default is 3.

https://docs.splunk.com/Documentation/Splunk/7.1.2/Admin/Indexesconf

0 Karma

diogofgm
SplunkTrust
SplunkTrust

check with btool which settings are being applied.

./splunk btool indexes list --debug prove_di_cold

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

ddrillic
Ultra Champion

Weird because you have frozenTimePeriodInSecs = 100

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...