Splunk Enterprise

Indexes.conf setting for 90 days retention?

abhi04
Communicator

Hi All,

I have total of 30 GB of total data to be indexed which after indexing will be 15 GB as per splunk average compressing.

I have a total of 4 indexers with 1 TB of disk space. Can you please let me know the indexes.conf setting on each indexer for a retention of 90 days of searchable data in splunk. Does the below settings work or there can be some improvements that can be made?

 

I got this from the splunk sizing app.

http://splunk-sizing.appspot.com/#ar=0&cdv=1&cr=90&ds=1024&hwr=14&i=4&v=30

 

 

indexes.conf

# volume definitions

 

[volume:hotwarm_cold]
path = /mnt/fast_disk
maxVolumeDataSizeMB = 996148
# index definition (calculation is based on a single index)

[index_name]
homePath = volume:hotwarm_cold/defaultdb/db
coldPath = volume:hotwarm_cold/defaultdb/colddb
thawedPath = $SPLUNK_DB/defaultdb/thaweddb
homePath.maxDataSizeMB = 53760
coldPath.maxDataSizeMB = 345600
maxWarmDBCount = 4294967295
frozenTimePeriodInSecs = 8985600
maxDataSize = auto

 

 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
This should be fine.
---
If this reply helps you, Karma would be appreciated.
0 Karma

abhi04
Communicator

@richgalloway , any suggestions regarding the maxHotBuckets and  maxWarmDBCount. Any best practise rearding those? What if I remove these two parameters and the config file looks like below. Will this be better or the previous settings?

 

# index definition (calculation is based on a single index)

[index_name]
homePath = volume:hotwarm_cold/defaultdb/db
coldPath = volume:hotwarm_cold/defaultdb/colddb
thawedPath = $SPLUNK_DB/defaultdb/thaweddb
homePath.maxDataSizeMB = 53760
coldPath.maxDataSizeMB = 345600
frozenTimePeriodInSecs = 8985600
maxDataSize = auto_high_volume

 

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...