Summary
This chapter was an exploration of how Splunk stores data. Since Splunk is a paid application, we started by looking at how licensing works in Splunk. We learned about the different licensing models, such as the Splunk Free and Splunk Enterprise licenses. We looked at the different kinds of events that count against the Splunk license and defined terms such as Splunk license groups, stacks, and pools. We ended that discussion by learning how to configure licenses using Splunk Web and the Splunk CLI. Indexes and buckets are the constructs used to store data in Splunk. We learned that indexes are a repository of data and contain multiple buckets. We learned about the different types of buckets (warm, cold, frozen, and thawed). We discovered that we could make changes to the way Splunk stores data by making changes to settings in indexes.conf
, such as maxDataSize
and frozenTimePeriodInSecs
. We saw how each of these settings determines when data rolls from one bucket to the next...