Splunk Search

What will break if I set coldPath to /dev/null?

richgalloway
SplunkTrust
SplunkTrust

I've been asked to size a Splunk installation with only 30 days of hot/warm data - no cold data. I've never heard of this before. I could probably set coldPath=/dev/null so warm data is deleted instead of being moved to cold, but can Splunk handle that?

---
If this reply helps you, Karma would be appreciated.
0 Karma

twinspop
Influencer

Just set maxTotalDataSizeMB and homePath.maxDataSizeMB to the same amount. No need for shenanigans with the locations.

[someindex]
maxTotalDataSizeMB     = 100000
homePath.maxDataSizeMB = 100000
frozenTimePeriodInSecs = 2592000
  • edit - added your 30 day limit
0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...