Splunk sets the index period and index size

Step 1:
Edit /opt/splunk/etc/apps/search/local/indexs.conf and add the last two lines under each index

[messages]
coldPath = $SPLUNK_DB/messages/colddb
enableDataIntegrityControl = 0
enableTsidxReduction = 0
homePath = $SPLUNK_DB/messages/db
thawedPath = $SPLUNK_DB/messages/thaweddb
bucketRebuildMemoryHint = 0
compre***awdata = 1
enableOnlineBucketRepair = 1
syncMeta = 1
frozenTimePeriodInSecs=2592000
maxTotalDataSizeMB = 15360

Step 2:
restart the splunk server

/opt/splunk/bin/splunk restart

Step three:

View settings or modify on the page

Click the settings in the upper right corner and select Index to
Splunk sets the index period and index size
view the index size is the same as in the configuration file, or you can edit the index size directly here.
Splunk sets the index period and index size

Guess you like

Origin blog.51cto.com/hbbdgyb/2546770