Getting Data In

maxTotalDataSizeMB max value or 0

adamw
Communicator

Can you set maxTotalDataSizeMB to 0, or optionally set it to an incredibly high number (90000000, or 90TB) in order to hopefully make the cold-to-frozen process only happen based on frozenTimePeriodInSecs. Basically time based retention instead of the maxTotalDataSizeMB?

Thanks,
--adam

chimbudp
Contributor

might be Splunk will auto-tune itself to go with the highest priority fields ?! not sure...
But, i hope that Splunk wont delete the data , it makes the index size to grow till max size

maxTotalDataSizeMB
frozenTimePeriodInSecs

0 Karma

sowings
Splunk Employee
Splunk Employee

Per the docs for indexes.conf, the maximum value is 4294967295 MB. Setting it that high would result in time-only retention.

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...