I have setup a Windows 2008 virtual machine with the latest Splunk version installed. I only have a total of 10 gig on the volume that Splunk is installed. I would like it to roll over (delete) after the database hits approx 8-8.5 gig of data. Is there any easy way to do this? I've looked into the index's and it appears to use the main db and the _internal the most. Do I have to set each of these to 4 GB each or is there another more straight forward way to do this? Or, do I set the maxTotalDataSizeMB to 8000 mb? Any info. would be greatly appreciated.
... View more