Using volumes to manage multiple indexes

Volumes combine pools of storage across different indexes so that they age out together. Let's make up a scenario where we have five indexes and three storage devices.

The indexes are as follows:

Name Data per day Retention required Storage needed 
web 50 GB no requirement ? 
security 1 GB 2 years 730 GB * 50 percent 
app 10 GB no requirement ? 
chat 2 GB 2 years 1,460 GB * 50 
percent 
web_summary 1 GB 1 years 365 GB * 50 percent 

Now let's say we have three storage devices to work with, mentioned in the following table:

Name Size 
small_fast 500 GB 
big_fast 1,000 GB 
big_slow 5,000 GB 

We can create volumes based on the retention time needed. Security and chat share the same retention requirements, so we ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.