当前位置:网站首页>How does data age in Splunk?
How does data age in Splunk?
2022-06-11 12:15:00 【shenghuiping2001】
Splunk The data entering the indexer is stored in a directory called a bucket . As data ages , Buckets go through several stages : heat 、 temperature 、 cold 、 frozen and thaw . as time goes on , Barrel from one stage “ rolling ” To the next stage .

- When data is first indexed , It will go into a Hot barrel . Hot buckets can be searched and actively written . An index can open multiple hot buckets at the same time
- When certain conditions occur ( for example , The hot storage bucket reaches a certain size or splunkd Restart ), The hot storage bucket becomes Warm storage barrel (“ Scroll to warm ”), And create a new hot storage bucket in its location . The warm bucket is searchable , But it will not actively write . There can be many warm buckets
- Once further conditions are met ( for example , The index reaches a certain maximum number of warm buckets ), The indexer began rolling the warm buckets to... According to their age cold bucket . It always chooses the oldest warm bucket to roll to the cold . When aging in this way , The barrel will continue to cool
- After a while , The cold storage bucket will scroll to Frozen state , At this point they will be archived or deleted .
The bucket aging strategy determines when buckets move from one stage to the next , You can edit index.conf To modify .
Reference documents :
Configure maximum index size - Splunk Documentation
You can also refer to my other blog: splunk index Parameter setting _shenghuiping2001 The blog of -CSDN Blog
边栏推荐
- 深度学习与CV教程(14) | 图像分割 (FCN,SegNet,U-Net,PSPNet,DeepLab,RefineNet)
- The wonderful use of XOR (C language)
- 解决swagger文档接口404的问题
- 纯数据业务的机器打电话进来时回落到了2G/3G
- Zhouhongyi's speech at the China Network Security Annual Conference: 360 secure brain builds a data security system
- JVM优化
- Flick grouping sets multidimensional aggregation and setting table state expiration time
- Notes on topic brushing (XIV) -- binary tree: sequence traversal and DFS, BFS
- 线程五种状态(线程生命周期)
- Where is it safer to open an account for soda ash futures? How much capital is needed for a transaction?
猜你喜欢

Flick controls window behavior (trigger, remover, allow delay, put late data into side output stream)

ftp服務器:serv-u 的下載及使用

反射真的很耗时吗,反射 10 万次,耗时多久。

flask 框架web开发视频笔记

Notes on topic brushing (XIV) -- binary tree: sequence traversal and DFS, BFS

Use of RadioButton in QT

flink 滚动窗口、滑动窗口、会话窗口、全局窗口

一般运维架构图

刷题笔记(十三)--二叉树:前中后序遍历(复习)

Hang up the interviewer
随机推荐
近期使用nodejs pinyin包时遇到的问题
Splunk健康检查orphaned searches
You call this shit MQ?
Sulley fuzzer learning
splunk 证书过期 使KV-store不能启动
YARN 切换ResourceManager(Failed to connect to server:8032 retries get failed due to exceeded maximum)
Flink data flow graph, parallelism, operator chain, jobgraph and executiongraph, task and task slot
创建线程的四种方式
中间人攻击之ettercap嗅探
12. AQS of abstractqueuedsynchronizer
9、聊聊ThreadLocal
Using fast and slow pointer method to solve the problem of array (C language)
Yarn switch ResourceManager (failed to connect to server:8032 retries get failed due to exceeded maximum)
The secret behind the Splunk bucket
Full Permutation (recursion, backtracking)
记一次 mysql 主从不同步问题排查
解决swagger文档接口404的问题
Record a troubleshooting of MySQL master-slave asynchrony
微信web开发者,如何学习web开发
11、Synchronized与锁升级