Splunk Enterprise

Long numbers in conf files

tomy8sctm
Engager

I want to set maxTotalDataSizeMB to 2000000 (~2TB). Is there are more human readable way of writing this? e.g.

  • 2,000,000
  • 2_000_000
  • 2e6
Labels (1)
Tags (1)
0 Karma
1 Solution

javiergn
Super Champion

Hi @tomy8sctm ,

I'm afraid that is not possible for most settings.

What I normally do is to add a comment just before that line indicating in a more human-readable way what I'm doing:

 

# 2 years = 730 days = 63,072,000 seconds
frozenTimePeriodInSecs = 63072000

# 2 TB = 2,097,152 MB
maxTotalDataSizeMB = 2097152

 

 Certain settings do allow more human readable ways:

maxQueueSize = [<integer>|<integer>[KB|MB|GB]|auto]

 

View solution in original post

javiergn
Super Champion

Hi @tomy8sctm ,

I'm afraid that is not possible for most settings.

What I normally do is to add a comment just before that line indicating in a more human-readable way what I'm doing:

 

# 2 years = 730 days = 63,072,000 seconds
frozenTimePeriodInSecs = 63072000

# 2 TB = 2,097,152 MB
maxTotalDataSizeMB = 2097152

 

 Certain settings do allow more human readable ways:

maxQueueSize = [<integer>|<integer>[KB|MB|GB]|auto]

 

tomy8sctm
Engager

Thanks for the answer @javiergn. Oh, well. I'll just have to leave all 6 of the 0s in a row! It would be good if Splunk added this functionality at some point.

0 Karma

javiergn
Super Champion

You can always log a request in Splunk Ideas and see what happens:

https://docs.splunk.com/Documentation/Community/1.0/community/SplunkIdeas

 

 Regards,
J

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...