I run a fairly small network, about 70 users, I have exceeded the 500MB limit 3 times. Once by about a megabyte, once by about 100MB and once by 500MB.
At first I figured it was due to my turning on auditing on our file server. It generates a lot of events which is great. But then I stuck in a couple fire plotter logs and noticed the indexing go through the roof. Here are the stats:
File 1: 589KB - Splunk reports 1.4 Million indexes, the file is only 20,109 lines long.
File 2: 24,872KB - Splunk reports 225,000 indexes and this file is 864,264 lines long.
File 3: 21,188KB - 192.402 indexes, 736,691 lines
See where I am going with this? These logs all have similar data in them but the indexes are all over the place. I understand that number of indexes is not necessarily proportial to filesize.But I would like to know what is causing the bloat in my logging.
I am up to 14 million indexes and have been barely running a month on a small LAN. Splunk seems to be struggling now on returning reports. It is a fairly beefy server 2.0GBz Xeon with 1.5GB ram, which I can beef up if necessary but my peak usage hasn't come close to the amount of RAM I have.
Can someone tell me what I am doing wrong?