If Splunk Crashes will I lose everything that was being indexed in the Hot Bucket?.....is it safe to configure Splunk to roll straight to the Warm bucket more quickly during indexing?
What is the best approach?
You should typically not lose a hot bucket as the result of a Splunk crash. In 4.2, the "recoverable indexes" feature makes the bucket structure much more robust in the event of crashes and (some) disk/filesystem failures.
http://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/Recoverableindexes
You should typically not lose a hot bucket as the result of a Splunk crash. In 4.2, the "recoverable indexes" feature makes the bucket structure much more robust in the event of crashes and (some) disk/filesystem failures.
http://docs.splunk.com/Documentation/Splunk/latest/ReleaseNotes/Recoverableindexes