Deployment Architecture

data not rolling to cold index

a212830
Champion

Hi,

I ran into disk issues recently, and I noticed that on one paticular high-volume index, the data is not rolling onto the cold path, which is filling up the hot/warm filesystem. How do I control this?

Tags (3)

lukejadamec
Super Champion

Information for configuring the index storage can be found here.
http://docs.splunk.com/Documentation/Splunk/5.0.2/Indexer/Configureindexstorage

Change the version in the upper right to the version you are running, but basically:

It will tell you that the:

maxWarmDBCount parameter will set the maximum number of warmdb directories. If this value is exceeded the oldest warm directories will roll to cold on your cold path. The default for this value is 300. Also, this value can be set at the global or per index level.

0 Karma

kphillipson
Path Finder

a212830...I was a520384 😉

0 Karma

kphillipson
Path Finder

To answer your question give this a read. It explains how you may never see cold buckets:
http://wiki.splunk.com/Deploy:BucketRotationAndRetention

To change advanced settings for a given index it will be in the local folder for the application it was created under. Follow the document for the indexes.conf for more options:
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf

0 Karma

lukejadamec
Super Champion

Well, prepare to be informed.

0 Karma

a212830
Champion

I guess that's my question - where do I set those? I have the location setup in indexes.conf, but no other settings exist.

0 Karma

lukejadamec
Super Champion

Have you verified that there are buckets that match the warm to cold roll settings?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...