Splunk Enterprise

Long numbers in conf files

tomy8sctm
Engager

I want to set maxTotalDataSizeMB to 2000000 (~2TB). Is there are more human readable way of writing this? e.g.

  • 2,000,000
  • 2_000_000
  • 2e6
Labels (1)
Tags (1)
0 Karma
1 Solution

javiergn
Super Champion

Hi @tomy8sctm ,

I'm afraid that is not possible for most settings.

What I normally do is to add a comment just before that line indicating in a more human-readable way what I'm doing:

 

# 2 years = 730 days = 63,072,000 seconds
frozenTimePeriodInSecs = 63072000

# 2 TB = 2,097,152 MB
maxTotalDataSizeMB = 2097152

 

 Certain settings do allow more human readable ways:

maxQueueSize = [<integer>|<integer>[KB|MB|GB]|auto]

 

View solution in original post

javiergn
Super Champion

Hi @tomy8sctm ,

I'm afraid that is not possible for most settings.

What I normally do is to add a comment just before that line indicating in a more human-readable way what I'm doing:

 

# 2 years = 730 days = 63,072,000 seconds
frozenTimePeriodInSecs = 63072000

# 2 TB = 2,097,152 MB
maxTotalDataSizeMB = 2097152

 

 Certain settings do allow more human readable ways:

maxQueueSize = [<integer>|<integer>[KB|MB|GB]|auto]

 

tomy8sctm
Engager

Thanks for the answer @javiergn. Oh, well. I'll just have to leave all 6 of the 0s in a row! It would be good if Splunk added this functionality at some point.

0 Karma

javiergn
Super Champion

You can always log a request in Splunk Ideas and see what happens:

https://docs.splunk.com/Documentation/Community/1.0/community/SplunkIdeas

 

 Regards,
J

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...