Hello All,
I have updated the indexes.conf file homePath.maxDataSizeMB from 13gb to 30gb & maxTotalDataSizeMB 13gb to 30gb.And after that from search result i am not able to see old days data.Can anyone provide information how to check and fix this by getting old data in splunk?
indexes.conf file values now:
#aws_riskinfo
[aws_riskinfo]
homePath = volume:hotwarm/aws_riskinfo/db
coldPath = volume:hotwarm/aws_riskinfo/colddb
thawedPath = /prod/appli_is/splunk_indexes/archives/ARCH1Y/aws_riskinfo/thaweddb
homePath.maxDataSizeMB = 30000
coldPath.maxDataSizeMB = 0
maxTotalDataSizeMB = 30000
maxWarmDBCount = 4294967295
frozenTimePeriodInSecs = 7776000
#maxDataSize = auto_high_volume
coldToFrozenDir = /prod/appli_is/splunk_indexes/archives/ARCH1Y/aws_riskinfo/frozen
Any knowledge available to fix this case?