Splunk Enterprise

How does splunk prune block signatures?

eidur
Engager

Hi all,

We have enabled data block signing as described in http://docs.splunk.com/Documentation/Splunk/latest/admin/ITDataSigning

However the _blocksignature index is growing very large. For 3 months of data it's already at 200GB. It also has some events older than our main index.

Is it possible to let splunk delete from this index when the relevant source data in the main index is purged?

What can we do to limit the disk usage by the block signatures? Preferably we would like to be able to validate data from a year ago, but that may be unrealistic based on these space requirements.

Tags (1)
0 Karma

dart
Splunk Employee
Splunk Employee

You can set the retention for that index the same as any other index.

dart
Splunk Employee
Splunk Employee

I'd suggest filing a support case for an enhancement request for this.

0 Karma

eidur
Engager

Thanks. So there's no way to link the retention so that block signatures are deleted when the relevant data in the main index is rolled to frozen?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...