Splunk Cloud Platform

Index Size limitations in Splunk Cloud

anandhalagaras1
Communicator

Hi Team,

We are using Splunk Cloud in our environment. Previously we are running with 7.1.6.2 Splunk Cloud version and when we were using this version I can able to create the Index and also I can able to provide the Max Size value of each index which i am creating.

But now we have upgraded to version 7.2.9.1 in Splunk Cloud hence when i navigated to Settings -->Index. And when i try to create a new index at that time there is no option as Max Size.

So can any of you help me why the max size field has been removed from 7.2.9.1 version and what would be the max size value by default it assigns when we create a index. Since few of the index will be grow larger so how it works.

Or is it an issue with 7.2.9.1 version and if we upgrade to latest version will it work.

So kindly check and update on the same.

Tags (1)
0 Karma

willemjongeneel
Communicator

Hello,

I asked this question before aswell and got the following answer:

Max index size is no longer a constrains in data retention. Only the retention period is causing the data to be rolled to frozen. By default Splunk Cloud comes with 90 times your daily license GB in storage. So if you would have all your indexes on 90 day retention, then you would have the exact right amount of storage. Would you exceed your maximum default storage, then Splunk will still keep ingesting and retaining your data and you will be contacted by your Splunk account team to either reduce storage usage or to purchase additional storage.

Kind regards,
Willem Jongeneel

0 Karma

anandhalagaras1
Communicator

Thank you for the detailed explanation. We too got the same reply from Splunk support team.

But additionally we got another information stating that if we move to version 8.0 then once again the feature MaxSize has been added back while we create the Index. So just want to know whether its a bug in this 7.2.9.1 version then how come will it be re enabled in 8.0 version.

If any one can help to respond then it would be really nice.

0 Karma

amiracle
Splunk Employee
Splunk Employee

This feature will return in the 8.0.x release of Splunk Cloud.

0 Karma

anandhalagaras1
Communicator

@amiracle,

Thanks for your response.

We want to know why the feature is in disabled state in 7.2.9.1 version so is it a bug or how it calculates the default max size of each index. Also for example if i try to create a new index then what would be the max size will be allocated.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...