Hi all,
We have enabled data block signing as described in http://docs.splunk.com/Documentation/Splunk/latest/admin/ITDataSigning
However the _blocksignature index is growing very large. For 3 months of data it's already at 200GB. It also has some events older than our main index.
Is it possible to let splunk delete from this index when the relevant source data in the main index is purged?
What can we do to limit the disk usage by the block signatures? Preferably we would like to be able to validate data from a year ago, but that may be unrealistic based on these space requirements.
You can set the retention for that index the same as any other index.
I'd suggest filing a support case for an enhancement request for this.
Thanks. So there's no way to link the retention so that block signatures are deleted when the relevant data in the main index is rolled to frozen?