Custom indexes are defined in indexes.conf. Each index stanza sets the storage paths, size limits, and retention policies.
Key settings include homePath (hot/warm buckets), coldPath (cold buckets), thawedPath (restored data), maxTotalDataSizeMB (total disk limit), and frozenTimePeriodInSecs (max age before freezing).
Always create dedicated indexes for different data sources — it improves search performance and lets you set different retention policies per data type.
[firewall_logs]
homePath = $SPLUNK_DB/firewall_logs/db
coldPath = $SPLUNK_DB/firewall_logs/colddb
thawedPath = $SPLUNK_DB/firewall_logs/thaweddb
maxTotalDataSizeMB = 500000
frozenTimePeriodInSecs = 7776000