Splunk Enterprise

How does splunk prune block signatures?

eidur
Engager

Hi all,

We have enabled data block signing as described in http://docs.splunk.com/Documentation/Splunk/latest/admin/ITDataSigning

However the _blocksignature index is growing very large. For 3 months of data it's already at 200GB. It also has some events older than our main index.

Is it possible to let splunk delete from this index when the relevant source data in the main index is purged?

What can we do to limit the disk usage by the block signatures? Preferably we would like to be able to validate data from a year ago, but that may be unrealistic based on these space requirements.

Tags (1)
0 Karma

dart
Splunk Employee
Splunk Employee

You can set the retention for that index the same as any other index.

dart
Splunk Employee
Splunk Employee

I'd suggest filing a support case for an enhancement request for this.

0 Karma

eidur
Engager

Thanks. So there's no way to link the retention so that block signatures are deleted when the relevant data in the main index is rolled to frozen?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...