Splunk Search

tsidx size limits

jtrucks
Splunk Employee
Splunk Employee

Is there a way to set a max size on the entire tsidxstats or even a single set of tsidxstats?

I have the Splunk for BlueCoat app running on a search head. It is filling up my disk even though /opt/splunk/var/lib/splunk/tsidxstats is a separate file system.

I can't find any way to limit the overall use of tsidxstats on a global or local level.

Any ideas?

--
Jesse Trucks
Minister of Magic
1 Solution

jtrucks
Splunk Employee
Splunk Employee

It turns out there is not a way to limit the size of tsidxstats by individual collections or in toto. This must be manually managed if tscollect is used to create the files.

--
Jesse Trucks
Minister of Magic

View solution in original post

kserra_splunk
Splunk Employee
Splunk Employee

There is an add-on called SA-UTILS which contains a file called tsidx_retention.conf , this file will give you the ability to age out these old tsidx files. More information about this file and process is documented in the below articles

http://docs.splunk.com/Documentation/VMW/3.1/Install/Considerationswhenusingtsidxnamespaces http://docs.splunk.com/Documentation/ES/3.0.1/Install/TSIDXnamespaces

jtrucks
Splunk Employee
Splunk Employee

It turns out there is not a way to limit the size of tsidxstats by individual collections or in toto. This must be manually managed if tscollect is used to create the files.

--
Jesse Trucks
Minister of Magic
Get Updates on the Splunk Community!

Meet Duke Cyberwalker | A hero’s journey with Splunk

We like to say, the lightsaber is to Luke as Splunk is to Duke. Curious yet? Then read Eric Fusilero’s latest ...

The Future of Splunk Search is Here - See What’s New!

We’re excited to introduce two powerful new search features, now generally available for Splunk Cloud Platform ...

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...