Splunk Cloud Platform

Index Size limitations in Splunk Cloud

anandhalagaras1
Contributor

Hi Team,

We are using Splunk Cloud in our environment. Previously we are running with 7.1.6.2 Splunk Cloud version and when we were using this version I can able to create the Index and also I can able to provide the Max Size value of each index which i am creating.

But now we have upgraded to version 7.2.9.1 in Splunk Cloud hence when i navigated to Settings -->Index. And when i try to create a new index at that time there is no option as Max Size.

So can any of you help me why the max size field has been removed from 7.2.9.1 version and what would be the max size value by default it assigns when we create a index. Since few of the index will be grow larger so how it works.

Or is it an issue with 7.2.9.1 version and if we upgrade to latest version will it work.

So kindly check and update on the same.

Tags (1)
0 Karma

willemjongeneel
Communicator

Hello,

I asked this question before aswell and got the following answer:

Max index size is no longer a constrains in data retention. Only the retention period is causing the data to be rolled to frozen. By default Splunk Cloud comes with 90 times your daily license GB in storage. So if you would have all your indexes on 90 day retention, then you would have the exact right amount of storage. Would you exceed your maximum default storage, then Splunk will still keep ingesting and retaining your data and you will be contacted by your Splunk account team to either reduce storage usage or to purchase additional storage.

Kind regards,
Willem Jongeneel

0 Karma

anandhalagaras1
Contributor

Thank you for the detailed explanation. We too got the same reply from Splunk support team.

But additionally we got another information stating that if we move to version 8.0 then once again the feature MaxSize has been added back while we create the Index. So just want to know whether its a bug in this 7.2.9.1 version then how come will it be re enabled in 8.0 version.

If any one can help to respond then it would be really nice.

0 Karma

amiracle
Splunk Employee
Splunk Employee

This feature will return in the 8.0.x release of Splunk Cloud.

0 Karma

anandhalagaras1
Contributor

@amiracle,

Thanks for your response.

We want to know why the feature is in disabled state in 7.2.9.1 version so is it a bug or how it calculates the default max size of each index. Also for example if i try to create a new index then what would be the max size will be allocated.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...