Getting Data In

What will happen when an index reaches its maximum size?

calvintkng
New Member

Just would like to know what will happen when an index reaches its maximum size? Will old data automatically be purged and continue to index new data?

Tags (2)
0 Karma
1 Solution

HiroshiSatoh
Champion

It becomes Frozen buckets.

Frozen :
Data rolled from cold. The indexer deletes frozen data by default, but you can also archive it. Archived data can later be thawed.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/HowSplunkstoresindexes

View solution in original post

HiroshiSatoh
Champion

It becomes Frozen buckets.

Frozen :
Data rolled from cold. The indexer deletes frozen data by default, but you can also archive it. Archived data can later be thawed.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/HowSplunkstoresindexes

HiroshiSatoh
Champion

If you run out of disk space, the indexer stops indexing.

http://docs.splunk.com/Documentation/Splunk/6.1.3/Indexer/Setlimitsondiskusage

maxDataSize,maxTotalDataSizeMB,frozenTimePeriodInSecs...etc

Please read the description of indexes.conf for the parameters to be set.

calvintkng
New Member

Thanks. So this mean if I set the maximum size of my index correct, I shouldn't run out of disk space. Right?

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...