Splunk Enterprise

Is it OK to manually delete unused warm buckets on my IDX?

ezmo1982
Path Finder

Hi,

My Splunk environment is on-prem. I have a single IDX which runs RHEL on a physical stand-alone server. Indexes are stored on a RAID 5 disk configuration on the same server.

My disk is starting to fill up and I was wondering if is is possible to manually delete older warm bucket files on my IDX (basically running an rm linux command)? The indexes in question are not being used/written to any more, so I dont need to search/access them again.

Is this OK to do? Will it create any inconsistency issues or errors in my Splunk env?

Thanks. 

Labels (1)
0 Karma

ezmo1982
Path Finder

i have retention policies set up on my indexes. It is based on age. It is set for all index types and i dont want to set up retention policies for individual ones. But i just want to know if manually deleting warm buckets cause any issues?

0 Karma

somesoni2
Revered Legend

Why not setup appropriate retention policies on your indexes (since you do not use/search old data), so that Splunk will automatically take care of the cleaning up space. You can setup retention based on age of data OR total size of index.

https://docs.splunk.com/Documentation/Splunk/8.2.2/Indexer/Setaretirementandarchivingpolicy

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...