Deployment Architecture

Any Risk if increased/decreased index data size

ips_mandar
Builder

Hi,
I have created one index of size 500GB(maxTotalDataSizeMb) and also included frozen path where data will get stored after 500Gb data gets completed. Now I want to know below-
1. If I Increased size of that index to 1TB then is there any risk involved of data gets deleted?
2. After changing to 1TB If I consider to reduce data size to 800 Gb then remaining 200Gb data will go to frozen path? is there any risk involved/any precaution neeeds to be taken to avoid data loss?
3. If I want to move frozen bucket to be searchable then I copied particular frozen bucket to thawed path and then after data retention those buckets moved to frozen path then will I have duplicate buckets? so I need to move frozen bucket to thawed path instead of copying it?
thanks,

0 Karma

richgalloway
SplunkTrust
SplunkTrust
  1. Increasing the size of an index does not result in data getting deleted.
  2. Since you have a frozen path, data will not be deleted. It will be moved to the frozen directory.
  3. Thawed data is not managed by Splunk so it will not be re-frozen. It will not be replicated or duplicated. When the thawed data is not longer needed, it must be removed manually.
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...