We're losing data to the frozen directory pre-maturely. We have requirements to keep data searchable for 5 years, but had left the MaxIndexSize at the default 500,000 MB and have now reached that limit earlier than expected. We have a coldtofrozen path specified, so our data is safe there, but just not searchable.
I have an open ticket to address an entire solution, but in the near term would like to stop the data from rolling to frozen.
If I set frozenTimePeriodInSecs for the index in question in indexes.conf, what behavior can I expect given that the index is already at max size? Will it have the effect I'm hoping for and simply allow the index to grow without regard to the 500,000 MB limit until such time as records meet the frozenTimePeriodInSecs value and can thus roll to frozen?
thanks for any advice.
Michael
Hi msantich,
Either if the max size of the index reaches maxTotalDataSizeMB
or if all events in a bucket are older than frozenTimePeriodInSecs
they will be rolled to frozen.
Read the docs http://docs.splunk.com/Documentation/Splunk/6.3.1/Indexer/Setaretirementandarchivingpolicy for more details.
Hope this helps ...
cheers, MuS
Hi msantich,
Either if the max size of the index reaches maxTotalDataSizeMB
or if all events in a bucket are older than frozenTimePeriodInSecs
they will be rolled to frozen.
Read the docs http://docs.splunk.com/Documentation/Splunk/6.3.1/Indexer/Setaretirementandarchivingpolicy for more details.
Hope this helps ...
cheers, MuS
ahhh...thank you MuS....
I appreciate the clarification....
Have a great day.