Splunk Search

hot_v* file not found but able to see file using locate

wuming79
Path Finder

Hi,

Referencing to http://docs.splunk.com/Documentation/Splunk/6.2.1/Capacity/Estimateyourstoragerequirements,
I'm trying to estimate my storage space on Linux. At /opt/splunk/var/lib/splunk/defaultdb, when I run "du -ch hot_v*", terminal says no such file or directory.

I did a locate hot_v and a list below came up and one of them in the db folder is hot_v1_12.
I then did a ls -a and I can't find hot_v1_12.

Anyone encounter this issue before?

alt text

Tags (1)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

The digits at the end of the hot bucket directories are sequential numbers. Hot buckets are rolled to warm (db_*) based on index configuration parameters, or when you stop/restart splunk. So those hot bucket names change all the time as new data comes in.
defaultdb is (by default) mapped to the 'main' index. If you don't ingest any data here, you won't have hot buckets.
I would recommend you use the Splunk Sizing Tool to figure out what your storage requirements are.
Select your daily data volume, retention settings, etc. and it will give you an estimate on per-indexer and total data storage needs for HOT/WARM and COLD volumes.

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...