Hey everyone, I have a question on Splunk Cloud Index MaxSize. I am having an issue with Splunk Cloud Index MaxSize. My index max size is set to 500GB, but the current size has reached 530GB, and some latest events (from last week) are not in the index but are going to archive storage. We have 3 months of searchable retention and 3 months of archive, and the archive dashboard is showing the latest event from last week. We have 8 indexers, which are clustered, and two dedicated search heads (not clustered). My question is, can I update the index maxsize (to unlimited) on the GUI, and will it replicate to all the indexers and 2 search heads, or should I open a support case for that? The second question is, can I restore the logs that went to archiving due to a maxsize issue to a searchable index again?
... View more