An index receives approximately 50GB of data per day per indexer at an even and consistent rate. The customer would like to keep this data searchable for a minimum of 30 days. In addition, they have hourly scheduled searches that process a week's worth of data and are quite sensitive to search performance. Given ideal conditions (no restarts, nor drops/bursts in data volume) , and following PS best practices, which of the following sets of indexes.conf settings can be leveraged to meet the requirements?
A) frozenTimePeriodInSecs, maxDataSize, maxVolumeDataSizeMB, maxHotBuckets
B) maxDataSize, maxTotalDataSizeMB, maxHotBuckets, maxGlobalDataSizeMB
C) maxDataSize, frozenTimePeriodInSecs, maxVolumeDataSizeMB
D) frozenTimePeriodInSecs, maxWarmDBCount, homePath.maxDataSizeMB, maxHotSpanSecs
Correct Answer:
Verified
Q50: A customer has written the following search:
Q51: A customer has a number of inefficient
Q52: A non-ES customer has a concern about
Q53: Which event processing pipeline contains the regex
Q54: A customer has downloaded the Splunk App
Q56: As a best practice which of the
Q57: A customer has 30 indexers in an
Q58: When monitoring and forwarding events collected from
Q59: Which of the following is the most
Q60: In an environment that has Indexer Clustering,
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents