Deployment Architecture

Backing up is not automated?

michael_lee
Path Finder

Hi,

What is the standard practice to clear up space ? for example I have configured splunk to receive syslogs everyday. However now my disk space keeps filling up. I want to backup my index (for the syslogs) , truncate data in the index and start afresh. Isn't there a seamless or "automated" way to do index backing up?
thanks

Tags (3)
0 Karma

s2_splunk
Splunk Employee
Splunk Employee

I'd suggest you read through this and familiarize yourself with how Splunk manages index data for you. Data is stored in buckets, which go through multiple stages, namely from HOT (actively written to) to WARM (read-only) to COLD (read-only) to FROZEN (not searchable).
You have full control over how long you keep data in each stage, either by specifying a time period or by limiting how much disk space each stage can consume.

This is fully automatic, but it DOES NOT replace backing up your data, if you are concerned about data loss. Take a gander at this for best practices around backing up your index data and/or consider using index replication to guard against indexer/data loss.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...