Splunk Cloud Platform

DDAS

yashb
Engager

Hi All,

Our DDAS usage has increased to 119.2%. What are some effective ways or best practices to optimize and reduce the usage? Any guidance or recommendations would be appreciated.

Thanks in advance!

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @yashb 

DDAS usage is based on the raw ingestion volume x number of days it’s stored for  

Ultimately there are 2 ways to reduce your DDAS (Active Searchable Storage) in Splunk Cloud. 
The first approach is to reduce your retention where possible, are there any indexes that you are keeping data for longer than you require it? Often Dev/Test environments can end up using lots of storage due to unnecessarily long retentions or big events like load/soak testing - for example. 

The other approach is to filter out data you don’t need, or strip specific fields/strings from raw events which are not required. For example you could drop any occurrence of an event containing “DEBUG” unless it’s required, or route it into an index with shorter retention.  You can achieve this in a number of ways depending on your environment, such as applying props/transforms at parsing/index time, using Ingest Actions or using Ingest Processor. 
I won’t go into specific examples here but if you want more help with a specific approach please let me know and I can provide sample configurations. 

 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was helpful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...