Deployment Architecture

why my indexes are filling up quickly

MAMAOUI
Explorer

Hello
I have an index(es) that are beginning to rapidly fill up,how can i determine the reason and solve it?!
Thanks
M&A

0 Karma
1 Solution

FrankVl
Ultra Champion

Take a look at your data and see which source / host is spiking and then investigate why that source / host is spiking and decide whether there is something wrong with that source / host that needs to be fixed, or whether this event volume is to be expected (and then adjust Splunk to scale to that demand).

View solution in original post

0 Karma

FrankVl
Ultra Champion

Take a look at your data and see which source / host is spiking and then investigate why that source / host is spiking and decide whether there is something wrong with that source / host that needs to be fixed, or whether this event volume is to be expected (and then adjust Splunk to scale to that demand).

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...