...onitor input stanza.
Without crcSalt Indexer is not reading this file.
We have setretirementandarchivingpolicyas 3 months for all splunk data. So after 3 months will splunk automatically read t...
...oldtofrozendir = $SPLUNK_DB/defaultdb/frozendb frozentimeperiodinsecs = 1209600
According to the "Setaretirementandarchivingpolicy" and "indexes.conf" documentation on splunk docs, the settings i...
...o convert the days to minutes value and then use that in abucket configuration. But I didn't find any proper example in Splunk.
Can anyone help me on this or any good documentation with a proper e...
My instance of Splunk currently has 9.4 TB of disk for indexing. We have 360GB per day being indexed and I can't increase the disk size to support this daily indexing.
I need to clean up indexed e...
I wanted to know if I am getting the data from some stream say TCP stream, where is the data stored? As I understand the data gets uploaded and indexed but some day can I get that data from Splunk? o...
Hi,
When the maxVolumeDataSizeMB for the primary volume is exceeded, will the events automatically roll over to the secondary volume?
Here are my settings:
[volume:primary]
path = /a...
Where and how can I set the data retention on Splunk?
Because I have seen there are many bow to set it like telemetry, main etc..
So it's really not clear...
...ommand line :
./splunk clean eventdata -f
and I have tried to erase all my log from the splunk folder, but I have still the same problem.
Please can someone help me?