Splunk Search

tsidx size limits

jtrucks
Splunk Employee
Splunk Employee

Is there a way to set a max size on the entire tsidxstats or even a single set of tsidxstats?

I have the Splunk for BlueCoat app running on a search head. It is filling up my disk even though /opt/splunk/var/lib/splunk/tsidxstats is a separate file system.

I can't find any way to limit the overall use of tsidxstats on a global or local level.

Any ideas?

--
Jesse Trucks
Minister of Magic
1 Solution

jtrucks
Splunk Employee
Splunk Employee

It turns out there is not a way to limit the size of tsidxstats by individual collections or in toto. This must be manually managed if tscollect is used to create the files.

--
Jesse Trucks
Minister of Magic

View solution in original post

kserra_splunk
Splunk Employee
Splunk Employee

There is an add-on called SA-UTILS which contains a file called tsidx_retention.conf , this file will give you the ability to age out these old tsidx files. More information about this file and process is documented in the below articles

http://docs.splunk.com/Documentation/VMW/3.1/Install/Considerationswhenusingtsidxnamespaces http://docs.splunk.com/Documentation/ES/3.0.1/Install/TSIDXnamespaces

jtrucks
Splunk Employee
Splunk Employee

It turns out there is not a way to limit the size of tsidxstats by individual collections or in toto. This must be manually managed if tscollect is used to create the files.

--
Jesse Trucks
Minister of Magic
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...