Knowledge Management

Creating an index: New Index Max Size vs Retention

aohls
Contributor

I am looking to setup a new summary index. When creating the index how does Max Size of Entire Index and Retention interact with one another. Would data get removed once one of these settings are hit? For example if I have 5GB and set the retention to 30 days, if I exceed 5GB at 20 days will it truncate the oldest days at that time; and the same if I set the retention to 30 days but only have 2GB out of 5 used, will it start truncating the old data?

0 Karma
1 Solution

Mayurmpatil
Path Finder

If maxTotalDataSizeMB(index size) is reached before frozenTimePeriodInSecs(retention period), data will be rolled to frozen before the configured time period has elapsed. If archiving has not been configured, unintended data loss can occur.

also if frozenTimePeriodInSecs(retention period) is reached before the index size of 5 gb is not reached , data will be rolled to frozen.

so in theory whatever reaches first will be applicable.

View solution in original post

Mayurmpatil
Path Finder

If maxTotalDataSizeMB(index size) is reached before frozenTimePeriodInSecs(retention period), data will be rolled to frozen before the configured time period has elapsed. If archiving has not been configured, unintended data loss can occur.

also if frozenTimePeriodInSecs(retention period) is reached before the index size of 5 gb is not reached , data will be rolled to frozen.

so in theory whatever reaches first will be applicable.

aohls
Contributor

@Mayurmpatil Thank you. We are just starting to use the summary index so this is helpful.

Mayurmpatil
Path Finder

@aohls - can you up vote my answer if you have happy with it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...