Splunk Cloud Platform

Index Size limitations in Splunk Cloud

anandhalagaras1
Communicator

Hi Team,

We are using Splunk Cloud in our environment. Previously we are running with 7.1.6.2 Splunk Cloud version and when we were using this version I can able to create the Index and also I can able to provide the Max Size value of each index which i am creating.

But now we have upgraded to version 7.2.9.1 in Splunk Cloud hence when i navigated to Settings -->Index. And when i try to create a new index at that time there is no option as Max Size.

So can any of you help me why the max size field has been removed from 7.2.9.1 version and what would be the max size value by default it assigns when we create a index. Since few of the index will be grow larger so how it works.

Or is it an issue with 7.2.9.1 version and if we upgrade to latest version will it work.

So kindly check and update on the same.

Tags (1)
0 Karma

willemjongeneel
Communicator

Hello,

I asked this question before aswell and got the following answer:

Max index size is no longer a constrains in data retention. Only the retention period is causing the data to be rolled to frozen. By default Splunk Cloud comes with 90 times your daily license GB in storage. So if you would have all your indexes on 90 day retention, then you would have the exact right amount of storage. Would you exceed your maximum default storage, then Splunk will still keep ingesting and retaining your data and you will be contacted by your Splunk account team to either reduce storage usage or to purchase additional storage.

Kind regards,
Willem Jongeneel

0 Karma

anandhalagaras1
Communicator

Thank you for the detailed explanation. We too got the same reply from Splunk support team.

But additionally we got another information stating that if we move to version 8.0 then once again the feature MaxSize has been added back while we create the Index. So just want to know whether its a bug in this 7.2.9.1 version then how come will it be re enabled in 8.0 version.

If any one can help to respond then it would be really nice.

0 Karma

amiracle
Splunk Employee
Splunk Employee

This feature will return in the 8.0.x release of Splunk Cloud.

0 Karma

anandhalagaras1
Communicator

@amiracle,

Thanks for your response.

We want to know why the feature is in disabled state in 7.2.9.1 version so is it a bug or how it calculates the default max size of each index. Also for example if i try to create a new index then what would be the max size will be allocated.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...