Getting Data In

How can I roll data from one location to another based on volume max size?

daniel333
Builder

All,

I have the following config in my indexes.conf

### define volumes
[volume:splunklocal]
path = /splunk_data
maxVolumeDataSizeMB = 600000

...

[akamai]
repFactor=auto
homePath   = volume:splunklocal/akamai/db
coldPath   = volume:splunklocal/akamai/colddb
thawedPath = $SPLUNK_DB/akamai/thaweddb
frozenTimePeriodInSecs = 7776000

The volume splunklocal is 600gigs. When this maxes out I was hoping to roll older logs to another volume called splunkbrozestorage. Is this possible? That is to say, I am not hitting my 90 days policy. I am hitting the volume size limitation. So I installed another volume of disks to roll to.

Any ideas? Docs?

0 Karma

tmarlette
Motivator

Do both volumes need to be the same bucket type? say both volumes are hot (homePath) or both volumes are cold (coldPath)

0 Karma

daniel333
Builder

A little bucket stupid here, I've largely left these the defaults. But if I am understanding you correctly you're asking if I want to move cold or warm. For the most part I am thinking I Just need to move the cold storage while leaving the warm where it is. I just don't know how to control the the point where we max the warm buckets out in this case?

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...