Hi,
I have max 63G available for splunk indexes. I have 3 main indexex and size should be like below.
abcd 38G
abcd-fine 15G
abcd-mon 10G
I have prepared the local/indexs.conf file for the same. Kindly review and suggest if it is good or I am missing something.
[abcd]
homePath = $SPLUNK_DB/abcd/db
coldPath = $SPLUNK_DB/abcd/colddb
thawedPath = $SPLUNK_DB/abcd/thaweddb
coldToFrozenScript = compressedExportabcd.sh
maxHotBuckets = 10
maxConcurrentOptimizes = 6
maxTotalDataSizeMB = 38912
maxHotIdleSecs = 86400
maxDataSize = 2048
[abcd-audit]
homePath = $SPLUNK_DB/abcd-audit/db
coldPath = $SPLUNK_DB/abcd-audit/colddb
thawedPath = $SPLUNK_DB/abcd-audit/thaweddb
coldToFrozenScript = compressedExportabcdAudit.sh
maxHotBuckets = 10
maxConcurrentOptimizes = 6
maxTotalDataSizeMB = 512
maxHotIdleSecs = 86400
maxDataSize = 50
[abcd-monitoring]
homePath = $SPLUNK_DB/abcd-mon/db
coldPath = $SPLUNK_DB/abcd-mon/colddb
thawedPath = $SPLUNK_DB/abcd-mon/thaweddb
coldToFrozenScript = compressedExportabcdMon.sh
maxHotBuckets = 10
maxConcurrentOptimizes = 6
maxTotalDataSizeMB = 11264
maxHotIdleSecs = 86400
maxDataSize = auto
Many thanks,
Bhuvnesh
... View more