Getting Data In

indexes.conf - volume definitions: Mebi Or Megabytes?

claudio_manig
Communicator

Hello Ninjas,

Does anybody have an idea of how to properly define a volume of 5TB of total storage in indexes.conf?

Technically, it should look like this:

[volume:hot1]
path = /mnt/fast_disk
maxVolumeDataSizeMB = 500000

As from a storage perspective, we use decimal separators from MB to TB and not the binary/mebi 1024. But some panels in the monitoring console made me struggle as the values do not sem to align with this logic.

So should it rather be:

    [volume:hot1]
    path = /mnt/fast_disk
    maxVolumeDataSizeMB = 5242880 

Using 1024 steps to calculate the 5 tb-

I havent found anything in the docs so anything official would be appreciated

Cheers
Claudio

Tags (2)
0 Karma

burwell
SplunkTrust
SplunkTrust

Great question! I have always interpreted the units/setting to use 1024 bytes so I have always configured my maxVolumeDataSizeMB that way.

I would have thought your second answer is the correct way, maxVolumeDataSizeMB = 5242880, but I can't find anything in the Splexicon or other Splunk docs page.

Whenever there are any Splunk answers about MB etc people always divide by 1024. For example
https://answers.splunk.com/answers/4609/convert-bytes-to-megabytes-in-report.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...