Deployment Architecture

Cap daily indexation of an index

internet_team
Explorer

Hello,

We currently have an index that has a size ranging from 3 to 7 Go per day, is there any way to limit the daily indexation to, lets say, 5 Go ?

Expected behaviour is : when the index size hits 5Go, it stops indexing new data to avoid license usage.

We already tried the thruput limitation in a limits.conf file and it does not work well enough for us. We'd also prefer not to have a Splunk alert launch a script on our servers.

Thanks in advance !

0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

There is no way to do this currently with Splunk.

internet_team
Explorer

Hello, thanks for the quick answer.

Is this going to be implemented in the near future ?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Not in the near to distant future. If you talk to you account rep, ask them to file an ERD and request this. That can help!!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...