So, volumes provide a better way to manage space when its shared among indexes.
We set a frozen time per index, then we set a maxVolumeDataSize for the volume that is set to ~90% of the storage partition size.
When the storage hits 90%, Splunk will go through ALL indexes on the volume and start rolling buckets until the size is below 90%.
Basically, we use the volume setting as the failsafe to ensure the storage doesn't get exhausted. We set high homepath and maxdb size per index, managing the total storage by the volume settings.
This works for us, there are advantages/disadvantages to this approach.
... View more