Installation

How to limit the daily volume of a specific index?

sysprg1
Explorer

I have one system which is the indexer, but there are multiple indexes (based upon projects)
Different projects have purchased licenses so I want to limit the indexes to various daily limits.
For example project A has purchased a 5Gig license and project B has purchased a 10Gig license.
I have project A data going to index X and project B data going to index Y.
Since both licenses are put into the auto_generated_pool_enterprise there is 15Gig volume allowed.
I want to limit project A (index X) to 5Gig per day and project B (index Y) to 10Gig per day.

If Project A (index X) gets more than 5Gig in a day, I don't want it to consume the other available license since that project didn't purchase it. I don't want to use a disk limit.

How can I limit the daily volume of a specific index?

Thanks,

Labels (2)

jasonbew
Engager

This would be useful to a lot of people I think, ie one app starts indexing abnormal volumes impacting the platform, it would be useful to be able to cap volumes per index to avoid the platform not indexing further data for other apps.

0 Karma

harsmarvania57
Ultra Champion

No, you cannot. Same answer given by MarioM

0 Karma

deepthi5
Path Finder

Even i am searching for the exact scenario to restrict the index by volume did some one find a way to do this

0 Karma

MarioM
Motivator

you cannot...license and license pooling are per indexer not per indexes.

The only option is to split your project per indexer.

vbalasubramania
New Member

is this still the case ? I see this response as of Sep 2012 and Iam using 6.1 fo rnow and ready to upgrade to 6.2 and am in the wsame exact scenario the original poster has raised.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...