Refine your search:

I have a 1GB license and I am trying to contain my daily indexing so that I don't exceed the maximum indexing volume allowed for my license. What would you recommend I do (configuration-wise) to attain this?

asked 08 Feb '10, 19:36

benstraw's gravatar image

benstraw
675214
accept rate: 80%


2 Answers:

What is the nature of the data that is causing you to exceed your index column and how is it arriving to splunk?

One option is to simply not index certain events, if you know which ones you'd like to exclude from indexing. You can do this by specifying a matching regex and routing these events to a nullqueue.

See the below docs on how to do this:

http://www.splunk.com/base/Documentation/Latest/Admin/Routeeventstospecificqueues

link

answered 08 Feb '10, 21:11

Gaurav's gravatar image

Gaurav ♦
3014
accept rate: 50%

To be more specific, you will want to route the events you don't need indexed to the nullQueue -- these events will be discarded and do not count against your license.

(26 Jan '11, 14:40) ftk ♦

A 100% effective, although unconventional, way to ensure that you never go over your indexing limit is to limit how fast the index can run.

$SPLUNK/etc/system/local/limits.conf:

[thruput]

maxKBps =

To figure out what the # should be, divide the daily license cap (1GB: 1073741824 bytes) by 86400 (seconds in a day), to get your max Kbps rate (12427 bytes/sec, or 12KB). This doesn't sound like much, and it isn't for a single second, but if splunk runs steadily all day long, you'll get close to your limit, but not go over it.

link

answered 26 Jan '11, 14:38

dpaper's gravatar image

dpaper
1967
accept rate: 50%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×327
×42

Asked: 08 Feb '10, 19:36

Seen: 1,042 times

Last updated: 26 Jan '11, 14:38

Copyright © 2005-2012 Splunk, Inc. All rights reserved.