Getting Data In

Index isn't shrinking when configuring Index size

gingerpower121
Explorer

I have the app Splunk_TA_microsoft_ad and I am trying to reduce the storage size of the index "wineventlog" from 50gb to around 15-20gb. I have tried updating the index in the GUI through the indexes page and updating the indexes.conf file and nothing seems to update. I've updated the indexes.conf file below with the config below and restarted splunk service.

/opt/splunk/etc/apps/Splunk_TA_microsoft_ad/local/indexes.conf

My config looks like this:

[wineventlog]
bucketRebuildMemoryHint = 0
compressRawdata = 1
enableDataIntegrityControl = 0
enableOnlineBucketRepair = 1
enableTsidxReduction = 0
maxTotalDataSizeMB = 15360
minHotIdleSecsBeforeForceRoll = 0
rtRouterQueueSize =
rtRouterThreads =
suspendHotRollByDeleteQuery = 0
syncMeta = 1
maxDataSize = 5120

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

Is indexes.conf only defined in one place? When you say "it doesn't update," I assume that you mean that your changes are saved in the file, but that nothing actually changes the size of the index.

I suggest that you check
1. Configuration file precedence - if indexes.conf is defined in multiple places, overlapping definitions are resolved based on the rules of precedence
2. Do you need to restart Splunk? When you manually edit indexes.conf, you need to restart Splunk for the changes to take effect.

View solution in original post

0 Karma

lguinn2
Legend

Is indexes.conf only defined in one place? When you say "it doesn't update," I assume that you mean that your changes are saved in the file, but that nothing actually changes the size of the index.

I suggest that you check
1. Configuration file precedence - if indexes.conf is defined in multiple places, overlapping definitions are resolved based on the rules of precedence
2. Do you need to restart Splunk? When you manually edit indexes.conf, you need to restart Splunk for the changes to take effect.

0 Karma

gingerpower121
Explorer

That was it. Total noob mistake on my part. Didn't realize it was also configured in:

/opt/splunk/etc/system/local/indexes.conf

0 Karma

lguinn2
Legend

Everybody does it. Some of us do it more than once!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...