Splunk® Enterprise

Monitoring Splunk Enterprise

Download manual as PDF

Download topic as PDF

Indexing: Indexes and Volumes

This topic is a reference for all of the Indexing: Indexes and volumes dashboards in the Monitoring Console. See "About the Monitoring Console."

What do these views show?

The indexes and volume dashboards consist of six individual dashboards about indexing, each consisting of several panels.

Altogether the indexes and volumes dashboards describe how disk is being used on your indexes. These views break down the data presented in the resource usage views.

Interpret results in these views

If your system is tight on storage, visit the indexes and volumes dashboards. Use this data to help you evaluate and revise your retention policy. See "How the indexer stores indexes" in Managing Indexers and Clusters of Indexers.

What to look for in these views

In the Indexes and Volumes: Instance dashboard, instances highlighted in blue are rolling buckets to frozen. See "How the indexer stores indexes" in Managing Indexers and Clusters of Indexers.

In the Indexes and Volumes: Deployment dashboard, information about data that is being frozen can be a red flag. The Indexes and Volumes panels display this information.

In the Index Detail: Deployment dashboard, check the Instances panel for indexers with Data Age vs. Frozen Age where the data is being frozen well before their age limit. Drilldowns in the dashboard help you investigate.

Indexing performance dashboards
Indexing: Inputs: HTTP Event Collector

This documentation applies to the following versions of Splunk® Enterprise: 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 6.6.5, 6.6.6, 6.6.7, 6.6.8, 6.6.9, 6.6.10, 6.6.11, 6.6.12, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.3.0, 7.3.1, 7.3.2

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters