Splunk Enterprise

Is there a way to find out what the oldest events are, by index,  in the local cache when running SmartStore?

ravida
Explorer

Is there a way to find out what the oldest events are, by index,  in the local cache when running SmartStore? I am able to ssh in and look at the local buckets, but is there a way to see it in the monitoring console or by query?

 

Thanks!

 

Joe

Labels (1)

AlessioP
Engager

Hi Ravida,

did you find a solution? My team and I are looking for the same type of check to verify that the "Hotlist Recency Seconds" is being respected.

did you try the command dbinspect with option cached(true or false)?

0 Karma

yeahnah
Motivator

I'm no expert on SmartStore by any means, but I doubt it would be possible.  From a Splunk search perspective the underlying storage layer is abstracted - it just looks like disk storage to Splunk - with SmartStore managing the cached data etc.

As the storage cache is a very dynamic environment, constantly changing with new data being ingested (hot buckets) and the search queries constantly being run (older raw data read back into cache) you would only be getting a brief snapshot in time of the oldest events in the an index - if this was possible.

Basically, what are you trying to understand with your query?  You've not provided any context to what you want to achieve.

0 Karma
Get Updates on the Splunk Community!

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...