<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disk is nearly full in Security</title>
    <link>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239373#M14858</link>
    <description>&lt;P&gt;how much data do you ingest daily and how long do you keep it?  Have you enabled/reviewed the distributed management console.  It should show you some of those numbers.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview"&gt;http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you need to remove data, you could always shrink your retention period to purge old events.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2016 00:26:55 GMT</pubDate>
    <dc:creator>maciep</dc:creator>
    <dc:date>2016-03-11T00:26:55Z</dc:date>
    <item>
      <title>Disk is nearly full</title>
      <link>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239372#M14857</link>
      <description>&lt;P&gt;Hi there!&lt;/P&gt;

&lt;P&gt;In the Splunk enterprise edition, the disk is getting almost full. However, it seems not to have enough data to fill a 200GB of disk space. How can I find out the details space usage as well as reduce that as necessary. Is there any way to automate the process for future?&lt;/P&gt;

&lt;P&gt;Best regards&lt;BR /&gt;
Hyder&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 03:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239372#M14857</guid>
      <dc:creator>tawrid</dc:creator>
      <dc:date>2016-03-10T03:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Disk is nearly full</title>
      <link>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239373#M14858</link>
      <description>&lt;P&gt;how much data do you ingest daily and how long do you keep it?  Have you enabled/reviewed the distributed management console.  It should show you some of those numbers.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview"&gt;http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you need to remove data, you could always shrink your retention period to purge old events.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 00:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239373#M14858</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2016-03-11T00:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Disk is nearly full</title>
      <link>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239374#M14859</link>
      <description>&lt;P&gt;Thanks for your answer. We have data in one drive only and that is filling up. However, there are plenty of spaces available in other drives of the machine. In terms of modifying the indexes.conf, have found the there are several of them available to change. We have 30-40 indexes available to change the configurations on coldPath, homePath and thawedPath in this file of /opt/splunk/etc/apps/search/local/indexes.conf. Is there anywhere can change these values globally? And for future creation of indexes will be selected by default this configuration as well. At this point we don't want to delete anything just to move the data to a new directory after 1 year for some indexes and 6 months for others. &lt;/P&gt;

&lt;P&gt;Any advise on configuration details will be highly appreciated.&lt;BR /&gt;
Cheers.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 22:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239374#M14859</guid>
      <dc:creator>tawrid</dc:creator>
      <dc:date>2016-03-21T22:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Disk is nearly full</title>
      <link>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239375#M14860</link>
      <description>&lt;P&gt;/opt/splunk/etc/apps/search/local/indexes.conf seems to be the right indexes.conf and you probably need to change each value separately and refer to the other drives.&lt;/P&gt;

&lt;P&gt;[xxxx]&lt;BR /&gt;
coldPath = $SPLUNK_DB/xxxx/colddb&lt;BR /&gt;
homePath = $SPLUNK_DB/xxxx/db&lt;BR /&gt;
thawedPath = $SPLUNK_DB/xxxx/thaweddb&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:09:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Disk-is-nearly-full/m-p/239375#M14860</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2020-09-29T09:09:55Z</dc:date>
    </item>
  </channel>
</rss>

