The following stanza is active in indexes.conf:
[cat_facts]
maxHotSpanSecs = 3600
frozenTimePeriodInSecs = 2630000
maxTota1DataSizeMB = 650000
All other related indexes.conf settings are default values.
If the event timestamp was 3739283 seconds ago, will it be searchable?
Which of the following is an acceptable channel value when using the HTTP Event Collector indexer acknowledgment capability?
All search-time field extractions should be specified on which Splunk component?
Which layers are involved in Splunk configuration file layering? (select all that apply)