Getting Data In

What is the expected behavior of setting maxTotalDataSizeMB=0

the_wolverine
Champion

The documentation infers:

http://docs.splunk.com/Documentation/Splunk/4.3.4/admin/Indexesconf

maxTotalDataSizeMB =

  • The maximum size of an index (in MB).
  • If an index grows larger than the maximum size, the oldest data is frozen.
  • This paremeter only applies to hot, warm, and cold buckets. It does not apply to thawed buckets.
  • Defaults to 500000.
  • Highest legal value is 4294967295
1 Solution

yannK
Splunk Employee
Splunk Employee

The expected behavior for maxTotalDataSizeMB=0 is to use an unlimited size for the index.
However there is a known bug for splunk 4.3.1 to 4.3.2 fixed in 4.3.3 that considered the
"0" value as a "zero" and shrinked the index.

see : http://docs.splunk.com/Documentation/Splunk/4.3.1/ReleaseNotes/Knownissues
and http://docs.splunk.com/Documentation/Splunk/4.3.3/ReleaseNotes/4.3.3

Setting maxTotalDataSizeMB = 0 causes the index to be deleted on restart (rather than allowing infinite index size, which is what one would expect). (SPL-49535)

View solution in original post

yannK
Splunk Employee
Splunk Employee

The expected behavior for maxTotalDataSizeMB=0 is to use an unlimited size for the index.
However there is a known bug for splunk 4.3.1 to 4.3.2 fixed in 4.3.3 that considered the
"0" value as a "zero" and shrinked the index.

see : http://docs.splunk.com/Documentation/Splunk/4.3.1/ReleaseNotes/Knownissues
and http://docs.splunk.com/Documentation/Splunk/4.3.3/ReleaseNotes/4.3.3

Setting maxTotalDataSizeMB = 0 causes the index to be deleted on restart (rather than allowing infinite index size, which is what one would expect). (SPL-49535)

the_wolverine
Champion

RUT ROH...

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...