...niversal Forwarder, the new hosts and source types are not showing up in my Splunk Search.
I have created a new index and configured that index as well on Splunk app.
I can see the new indexer is g...
Hi,
We are running Splunk v splunk-7.0.0-c8a78efdd40f.x86_64 right now and we have a problem we the internaldb indexsize. Although we configured a maximum of 5gb it just keeps getting bigger (t...
According to documentation:
The maxTotalDataSizeMB and frozenTimePeriodInSecs attributes in indexes.conf help determine when buckets roll from cold to frozen, allowing you to configure data r...
...ldest value
of latest time (for a given bucket) across all indexes in the volume,
until the volume is below the maximumsize. This is the trim operation.
This can cause buckets to be chilled [m...
HI
We have installed a SH and 4 INDEXERS(Non Clustered). We have installed our app to the SH only with our indexers=mlc_live and or datamodels.
We have set up the forwarders to send data to t...
Hello -
I am getting the following warning:
"IndexConfig - Home path size limit cannot accomodate maximum number of hot buckets with specified bucket size because homePath.maxDataSizeMB is t...
...hought of so far:
search index=myindex | reverse | head 100
search index=myindex | tail 100
Both are very slow while the following (the opposite of what I want) is fast
search index=m...
...es.
Each index on the indexer is configured to grow up to 750 MB and keep the data for 30 days.
However, when I do a search over the last 30 days, I'm missing the oldest events. The last ten d...