Quantcast
Channel: Questions in topic: "indexes.conf"
Browsing all 236 articles
Browse latest View live

How can I duplicate the "Indexes" settings page?

I am wondering how the "Indexes" page under Settings is generated. Is there a way that I can pull the same information that is contained there without doing a search/summation over all of my data? This...

View Article


vix.input.1.et.regex - Log directory only contains year, month, and day. How...

When I perform a query "index=api" with date range for example 07/07/2015 - 07/07/2015, I only get results within the first second of midnight on 07/07/2015. But if I perform the same query with date...

View Article


How to configure indexes.conf to have indexed data deleted after 1 day or 24...

Hi splunkers, I want to achieve 1 day retention for indexed data. How can I achieve this? I have a cluster setup with RF=3 and SF=3. As far as my understanding, I can set frozenTimePeriodInSecs = 86400...

View Article

How to index two different datestamps in a single sourcetype?

We had logs initially with timestamp: `[05/18/15 6:00:02.3898 AM]` With the latest release, the timestamp in logs changed to `[05/18/15 6:00:02.3898]`. There is no local equivalent for time (AM or PM)....

View Article

How to send warm data to cold on a separate local partition?

Local E drive is full and I need to send the "warm" data to "cold" on another partition (D) I set up `coldPath = D:\SplunkColdData` in the local indexes.conf file, but it's not working.

View Article


Can props.conf and indexes.conf be split for more clear structure?

Hi, as mentioned in the title I'm wondering, if the props.conf or indexes.conf can be split for a more clear structure. Does anybody do this? Best regards, Yannic

View Article

All historical data gone after setting up warm/cold buckets. How can I get my...

I set up warm/cold buckets to offload data to a separate partition due to disk space issues. After configuring the indexes.conf file and restarting the splunkd service, all historical data is gone...

View Article

Initiating Splunk on AWS AMI, why am I getting "Search not executed: The...

I've initiated an AMI of Splunk on a t2.medium instance, and even before I've actively used it, I get Search not executed: The minimum free disk space (5000MB) reached for...

View Article


How to restrict access to one certain index without changing all the other...

The use case seems simple enough: **Lets say we have index `sensitive_data` that contains... sensitive data. We want to ensure that ONLY role `data-team` has access to this index. How to do this...

View Article


Why is the cluster master of a multisite indexer cluster not showing new...

I am setting up a multisite cluster with 2 indexers and 1 sh in each site, 2 sites (for now). I've created 2 extra indexes in `$SPLUNK_HOME/etc/master-apps/_cluster/local/indexes.conf` and successfully...

View Article

Where do I place indexes.conf in an indexer clustering environment?

Hi everyone, I have the indexes.conf, but I'm not sure where to place it inside my cluster environment. I thought I had to place it on the master, inside the folder master-app, but this folder is...

View Article

How to move fishbucket data to a warm bucket?

I wish to move all data which are in the fishbucket to warm bucket. Is there any command to do this?

View Article

Determining indexes.conf settings for all indexes combined

I've spent hours studying the documentation and articles outside of splunkbase about configuring indexing, and I'm still confused, and our indexing isn't working as expected. This shouldn't be that...

View Article


Indexer Cluster: Under default in indexes.conf, when I use paths /indx/hot...

Hey there... In my default section of my indexes.conf file (used for the internal spunk indexes), I have primary defined as `/indx/hot` and secondary `/indx/cold`. When I use these paths and create a...

View Article

Can I, Should I, Change the default rotation from Warm To Cold Buckets

The default for rotation from warm to cold is 300. I am retaining about 1 years worth of data in all indexes and most of that data is kept in warm buckets I have about 13.22 TB of "homepath" data and...

View Article


How to index two different datestamps in a single sourcetype?

We had logs initially with timestamp: `[05/18/15 6:00:02.3898 AM]` With the latest release, the timestamp in logs changed to `[05/18/15 6:00:02.3898]`. There is no local equivalent for time (AM or PM)....

View Article

How to send warm data to cold on a separate local partition?

Local E drive is full and I need to send the "warm" data to "cold" on another partition (D) I set up `coldPath = D:\SplunkColdData` in the local indexes.conf file, but it's not working.

View Article


Can props.conf and indexes.conf be split for more clear structure?

Hi, as mentioned in the title I'm wondering, if the props.conf or indexes.conf can be split for a more clear structure. Does anybody do this? Best regards, Yannic

View Article

All historical data gone after setting up warm/cold buckets. How can I get my...

I set up warm/cold buckets to offload data to a separate partition due to disk space issues. After configuring the indexes.conf file and restarting the splunkd service, all historical data is gone...

View Article

Initiating Splunk on AWS AMI, why am I getting "Search not executed: The...

I've initiated an AMI of Splunk on a t2.medium instance, and even before I've actively used it, I get Search not executed: The minimum free disk space (5000MB) reached for...

View Article
Browsing all 236 articles
Browse latest View live


Latest Images