Deployment Architecture

What factors into how Splunk creates new hot buckets?

jitsinha
Path Finder

Can anybody put some light on the factors based on why Splunk creates new Hot buckets??

Like maxDataSize and maxHotBuckets - these are the two factors responsible for rollover from hot to warm.

Labels (1)
0 Karma

MuS
Legend

Hi jitsinha,

you can find everything in the docs http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/HowSplunkstoresindexes :

Newly indexed data goes into a hot bucket, which is a bucket that's both searchable and actively being written to. After the hot bucket reaches a certain size, it becomes a warm bucket ("rolls to warm"), and a new hot bucket is created. 

and / or in the wiki :

hope this helps ...

cheers, MuS

anwarmian
Communicator

I gave an up point because MuS mentions that hot buckets are both searchable and actively being written to. This a good point. Warm buckets, on the other hand, are searchable but NOT actively written to. Splunk restart also rolls hot to warm.

0 Karma

jitsinha
Path Finder

anyone please??

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...