Deployment Architecture

If I comment out the "enableTsidxReduction", will TSIDX be recreated?

mcdp_matsumoto
New Member

If I comment out the following settings, will TSIDX be recreated?

enableTsidxReduction = true
timePeriodInSecBeforeTsidxReduction = 864000

The following is the contents of indexes.conf

vi /opt/splunk/etc/master-apps/_cluster/local/indexes.conf

[onepocket]
coldPath = $SPLUNK_DB/onepocket/colddb
homePath = $SPLUNK_DB/onepocket/db
thawedPath = $SPLUNK_DB/onepocket/thaweddb

enableTsidxReduction = true
timePeriodInSecBeforeTsidxReduction = 864000

frozenTimePeriodInSecs = 63072000

repFactor = auto
Labels (1)
Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Turning off tsidx reduction does not undo the reduction. To restore the tsidx files you must rebuild the buckets. See https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/Reducetsidxdiskusage#Restore_reduced_buck...

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Turning off tsidx reduction does not undo the reduction. To restore the tsidx files you must rebuild the buckets. See https://docs.splunk.com/Documentation/Splunk/8.0.3/Indexer/Reducetsidxdiskusage#Restore_reduced_buck...

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...