Deployment Architecture

data not rolling to cold index

a212830
Champion

Hi,

I ran into disk issues recently, and I noticed that on one paticular high-volume index, the data is not rolling onto the cold path, which is filling up the hot/warm filesystem. How do I control this?

Tags (3)

lukejadamec
Super Champion

Information for configuring the index storage can be found here.
http://docs.splunk.com/Documentation/Splunk/5.0.2/Indexer/Configureindexstorage

Change the version in the upper right to the version you are running, but basically:

It will tell you that the:

maxWarmDBCount parameter will set the maximum number of warmdb directories. If this value is exceeded the oldest warm directories will roll to cold on your cold path. The default for this value is 300. Also, this value can be set at the global or per index level.

0 Karma

kphillipson
Path Finder

a212830...I was a520384 😉

0 Karma

kphillipson
Path Finder

To answer your question give this a read. It explains how you may never see cold buckets:
http://wiki.splunk.com/Deploy:BucketRotationAndRetention

To change advanced settings for a given index it will be in the local folder for the application it was created under. Follow the document for the indexes.conf for more options:
http://docs.splunk.com/Documentation/Splunk/latest/Admin/Indexesconf

0 Karma

lukejadamec
Super Champion

Well, prepare to be informed.

0 Karma

a212830
Champion

I guess that's my question - where do I set those? I have the location setup in indexes.conf, but no other settings exist.

0 Karma

lukejadamec
Super Champion

Have you verified that there are buckets that match the warm to cold roll settings?

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...