I understand Splunk provides multiple means to control the disk size for indexing, and I want to understand better around minFreeSpace option which is specified in server.conf.
If the actual usage of the filesystem exceeds the threshold specified by minFreeSpace, how will the data which was seized from being indexed be handled after the disk space gets freed ? As long as the ack on Forwarder is enabled, will the data again be collected and indexed, or will it be just lost ?
I assume the result may be varied across types of input, forwarder, tcp/udp, HEC, etc ...
Any detailed answer would be highly appreciated.
... View more