Getting Data In

index size

dall
Path Finder

in my stand alone environment 

indexes.conf:

maxDataSize=100mb

maxTotalDataSizemb=200000

but in ui one of index current size is 40gb max size is 500gb

as i understood that maxdata size =100mb means when hot bucket ll reach 100mb that ll pass to anaotherbucket

and maxtotaldatasizemb=200000=200gb(hot+warm+cold)

than current size of 40gb means that data ll b in hot bucket or what ?

please clarify this one

 

Labels (1)
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @dall,

when you configure an index in UI you have to declare the app containing the indexes.conf and few informations (paths, maxdatasize and few other thing).

using UI you don't setup retention etc...

You can setup these options later, modifying indexes.conf files.

For more infos see at https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Indexesconf

I hint to follow the admin certification path to learn about this.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @dall,

your configuration means that:

  • you have 100 MB of hot buckets (as you said) that continously roll to warm because it's a very small dimension,
  • warm and cold buckets have a size of 40 GB (minus 20 hot) and can grow to 200 GB.
  • the size of warm buckets depends on the number of warm buckets, because when you have 300 warm buckets, Splunk starts to roll to cold.
  • Also for this reason it's better to have e greater dimension for buckets.

Anyway, these values are set for each index, so if you have an index with a diferent configuration (500 max data size) probably it's differently set.

you can see the indexes configuration in two ways:

  • using btool you can see all the indexes active configurations, so you can find the configuuration of the different index: $SPLUNK_HOME/bin/splunk cmd btool indexs list --debug > indexes.txt;
  • using [Settings -- Indexes ] you can find which is the app where an index is configurated;

so you can intervene to change configurations.

Ciao.

Giuseppe

0 Karma

dall
Path Finder

when created index in ui gave homepath,coldpath,thawedpath 

not configured in indexes.conf for that particular index 

not given any retention period ,maxdatasize and all

can i set now for that index and others also

is there any issue i ll face if i ll add in indexes.conf

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dall,

when you configure an index in UI you have to declare the app containing the indexes.conf and few informations (paths, maxdatasize and few other thing).

using UI you don't setup retention etc...

You can setup these options later, modifying indexes.conf files.

For more infos see at https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Indexesconf

I hint to follow the admin certification path to learn about this.

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @dall,

good for you.

Ciao and happy splunking.

Giuseppe.

P.S.: Karma Points are appreciated 😉

0 Karma

dall
Path Finder

thank u so much @gcusello 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...