Getting Data In

index size

dall
Path Finder

in my stand alone environment 

indexes.conf:

maxDataSize=100mb

maxTotalDataSizemb=200000

but in ui one of index current size is 40gb max size is 500gb

as i understood that maxdata size =100mb means when hot bucket ll reach 100mb that ll pass to anaotherbucket

and maxtotaldatasizemb=200000=200gb(hot+warm+cold)

than current size of 40gb means that data ll b in hot bucket or what ?

please clarify this one

 

Labels (1)
1 Solution

gcusello
Legend

Hi @dall,

when you configure an index in UI you have to declare the app containing the indexes.conf and few informations (paths, maxdatasize and few other thing).

using UI you don't setup retention etc...

You can setup these options later, modifying indexes.conf files.

For more infos see at https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Indexesconf

I hint to follow the admin certification path to learn about this.

Ciao.

Giuseppe

View solution in original post

gcusello
Legend

Hi @dall,

your configuration means that:

  • you have 100 MB of hot buckets (as you said) that continously roll to warm because it's a very small dimension,
  • warm and cold buckets have a size of 40 GB (minus 20 hot) and can grow to 200 GB.
  • the size of warm buckets depends on the number of warm buckets, because when you have 300 warm buckets, Splunk starts to roll to cold.
  • Also for this reason it's better to have e greater dimension for buckets.

Anyway, these values are set for each index, so if you have an index with a diferent configuration (500 max data size) probably it's differently set.

you can see the indexes configuration in two ways:

  • using btool you can see all the indexes active configurations, so you can find the configuuration of the different index: $SPLUNK_HOME/bin/splunk cmd btool indexs list --debug > indexes.txt;
  • using [Settings -- Indexes ] you can find which is the app where an index is configurated;

so you can intervene to change configurations.

Ciao.

Giuseppe

0 Karma

dall
Path Finder

when created index in ui gave homepath,coldpath,thawedpath 

not configured in indexes.conf for that particular index 

not given any retention period ,maxdatasize and all

can i set now for that index and others also

is there any issue i ll face if i ll add in indexes.conf

0 Karma

gcusello
Legend

Hi @dall,

when you configure an index in UI you have to declare the app containing the indexes.conf and few informations (paths, maxdatasize and few other thing).

using UI you don't setup retention etc...

You can setup these options later, modifying indexes.conf files.

For more infos see at https://docs.splunk.com/Documentation/Splunk/8.1.1/Admin/Indexesconf

I hint to follow the admin certification path to learn about this.

Ciao.

Giuseppe

gcusello
Legend

Hi @dall,

good for you.

Ciao and happy splunking.

Giuseppe.

P.S.: Karma Points are appreciated 😉

0 Karma

dall
Path Finder

thank u so much @gcusello 

0 Karma
Get Updates on the Splunk Community!

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...