Splunk Enterprise

Long numbers in conf files

tomy8sctm
Engager

I want to set maxTotalDataSizeMB to 2000000 (~2TB). Is there are more human readable way of writing this? e.g.

  • 2,000,000
  • 2_000_000
  • 2e6
Labels (1)
Tags (1)
0 Karma
1 Solution

javiergn
Super Champion

Hi @tomy8sctm ,

I'm afraid that is not possible for most settings.

What I normally do is to add a comment just before that line indicating in a more human-readable way what I'm doing:

 

# 2 years = 730 days = 63,072,000 seconds
frozenTimePeriodInSecs = 63072000

# 2 TB = 2,097,152 MB
maxTotalDataSizeMB = 2097152

 

 Certain settings do allow more human readable ways:

maxQueueSize = [<integer>|<integer>[KB|MB|GB]|auto]

 

View solution in original post

javiergn
Super Champion

Hi @tomy8sctm ,

I'm afraid that is not possible for most settings.

What I normally do is to add a comment just before that line indicating in a more human-readable way what I'm doing:

 

# 2 years = 730 days = 63,072,000 seconds
frozenTimePeriodInSecs = 63072000

# 2 TB = 2,097,152 MB
maxTotalDataSizeMB = 2097152

 

 Certain settings do allow more human readable ways:

maxQueueSize = [<integer>|<integer>[KB|MB|GB]|auto]

 

tomy8sctm
Engager

Thanks for the answer @javiergn. Oh, well. I'll just have to leave all 6 of the 0s in a row! It would be good if Splunk added this functionality at some point.

0 Karma

javiergn
Super Champion

You can always log a request in Splunk Ideas and see what happens:

https://docs.splunk.com/Documentation/Community/1.0/community/SplunkIdeas

 

 Regards,
J

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...