Documentation: 3.3.4
Print Version Contents
This page last updated: 07/10/08 02:07pm

Manage your indexes

In previous Splunk releases, you used the command line interface (CLI) to manage your indexes. Now, you can view your indexes, edit their properties, and add new indexes from the Admin page of Splunk Web.

This topic discusses using Splunk Web to view and edit your indexes. To define a custom index, refer to the Create new index topic.

View and manage indexes

In Splunk Web, you can view and edit all your indexes from the Admin page:

1. On the upper righthand corner of any of the dashboards, click Admin.

2. From the lefthand navigation list, click Indexes.

This takes you to the Admin > Indexess: View/Manage Indexes page which displays a table of all your indexes and their properties, including:.

  • The home path, or directory.
  • The current size in MB.
  • The maximum size in MB.
  • A count of events.
  • A timestamp for the latest event.
  • A timestamp for the earliest event.

Edit index properties

From the Admin > Index: View/Manage Indexes page, click an index name to view and edit that index's properties. Properties that you cannot change are grayed out and include:

  • The index's name.
  • The path to the fields and hot/warm databases.
  • The path to the cold databases.
  • The path to the thawed databases.

Properties that you can redefine include:

  • The maximum size (in MB) of the hot database.
  • The maximum size (in MB) of an index.

After you make your changes, click Update. Then, restart Splunk to apply your changes.

Important: To apply any changes that you make to the indexes, such as editing properties or adding a new index, you must restart Splunk. In Splunk Web, you can restart the Splunk server from Admin > Server: Control Server. Just click Restart Now.

Previous: About indexes and indexing    |    Next: Create new index

Comments

No comments have been submitted.

Log in to comment.