Hi,
I wanna ask about indexing.
For Example, if I have 10 GB HDD, and have Splunk 500 MB license; I set the max free space for Splunk to stop indexing when the free space of HDD is 2 GB (2000 MB) -- set from Manager - System Settings.
If one day, the free HDD space is 2GB, Splunk will pause to index.
For my scenario,
Let say the administrator never monitor the space for unknown reasons... :)
How about the new data? they may not indexed by Splunk and return to device, and because the device has limited space for the logs, the logs may be flushed. and the administrator will lost the logs from the splunk index either from the device.
How to set Splunk to automatically delete the old data? say about automatically delete data above 30 days...
Please guide me how to set this?
thanks for the inputs from all you, guys :)
Tags:
Share
Facebook
-
▶ Reply to This