Splunk Search

hot_v* file not found but able to see file using locate

wuming79
Path Finder

Hi,

Referencing to http://docs.splunk.com/Documentation/Splunk/6.2.1/Capacity/Estimateyourstoragerequirements,
I'm trying to estimate my storage space on Linux. At /opt/splunk/var/lib/splunk/defaultdb, when I run "du -ch hot_v*", terminal says no such file or directory.

I did a locate hot_v and a list below came up and one of them in the db folder is hot_v1_12.
I then did a ls -a and I can't find hot_v1_12.

Anyone encounter this issue before?

alt text

Tags (1)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

The digits at the end of the hot bucket directories are sequential numbers. Hot buckets are rolled to warm (db_*) based on index configuration parameters, or when you stop/restart splunk. So those hot bucket names change all the time as new data comes in.
defaultdb is (by default) mapped to the 'main' index. If you don't ingest any data here, you won't have hot buckets.
I would recommend you use the Splunk Sizing Tool to figure out what your storage requirements are.
Select your daily data volume, retention settings, etc. and it will give you an estimate on per-indexer and total data storage needs for HOT/WARM and COLD volumes.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...