Deployment Architecture

If a cold to frozen script fails, what happens?

roychen
Path Finder

Hello,

In indexes.conf, we can specify a value for coldToFrozenScript, to run a specific script when cold buckets are rolled to frozen.

What happens if the script fails to execute, or returns an error code, etc, when a rolling of cold buckets to frozen is triggered?

Will the cold buckets be deleted in this case?

Thanks!

Tags (1)
0 Karma
1 Solution

roychen
Path Finder

According to Splunk support, if the script to roll cold buckets to frozen fails to run, the cold buckets will not be deleted.

If these cold buckets are not deleted, and new incoming data would cause the index to exceed its configured size, Splunk will not delete the cold buckets to make room. Instead, the index will grow in size till the script is fixed.

View solution in original post

roychen
Path Finder

According to Splunk support, if the script to roll cold buckets to frozen fails to run, the cold buckets will not be deleted.

If these cold buckets are not deleted, and new incoming data would cause the index to exceed its configured size, Splunk will not delete the cold buckets to make room. Instead, the index will grow in size till the script is fixed.

the_wolverine
Champion

You can configure deletion by age AND by size. The condition that matches first will prevail. It is possible that the second condition will never match due to the first condition.

0 Karma

chimbudp
Contributor

If we had set the limit of index to a particular smaller value (say 100MB),Will Splunk overrides the value to auto and make the index size to grow ?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...