<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288096#M10936</link>
    <description>&lt;P&gt;Splunk 6.6.3, clustered env. One of our indexers reporting high disk usage. Traced it down to &lt;CODE&gt;/opt/splunk/var/run/splunk/cluster/search-buckets&lt;/CODE&gt; containing many &lt;CODE&gt;search_sitedefault_gen*.csv.gz&lt;/CODE&gt; and &lt;CODE&gt;summarize_sitedefault_gen*.csv.gz&lt;/CODE&gt; files going back to 22 days ago (December 12 at this time). I deleted older ones to stop triggering our disk use alerts.&lt;/P&gt;
&lt;P&gt;Whats creating these files and why?&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2022 13:16:16 GMT</pubDate>
    <dc:creator>richarddicaire</dc:creator>
    <dc:date>2022-03-31T13:16:16Z</dc:date>
    <item>
      <title>Why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288096#M10936</link>
      <description>&lt;P&gt;Splunk 6.6.3, clustered env. One of our indexers reporting high disk usage. Traced it down to &lt;CODE&gt;/opt/splunk/var/run/splunk/cluster/search-buckets&lt;/CODE&gt; containing many &lt;CODE&gt;search_sitedefault_gen*.csv.gz&lt;/CODE&gt; and &lt;CODE&gt;summarize_sitedefault_gen*.csv.gz&lt;/CODE&gt; files going back to 22 days ago (December 12 at this time). I deleted older ones to stop triggering our disk use alerts.&lt;/P&gt;
&lt;P&gt;Whats creating these files and why?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 13:16:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288096#M10936</guid>
      <dc:creator>richarddicaire</dc:creator>
      <dc:date>2022-03-31T13:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288097#M10937</link>
      <description>&lt;P&gt;We're now seeing additional indexers having disk usage issues from the above, can anyone shed any light?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 15:33:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288097#M10937</guid>
      <dc:creator>richarddicaire</dc:creator>
      <dc:date>2018-01-05T15:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288098#M10938</link>
      <description>&lt;P&gt;We had recently a similar but different path issue at &lt;A href="https://answers.splunk.com/answers/592064/why-does-optsplunkvarrunsearchpeers-fill-up.html"&gt;Why does /opt/splunk/var/run/searchpeers fill up?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 16:35:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288098#M10938</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-01-05T16:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288099#M10939</link>
      <description>&lt;P&gt;@ddrillic thanks for responding but not related. I need to know what is creating the above files in /opt/splunk/var/run/splunk/cluster/search-buckets. I just had to delete files from all of my indexers to have available space. Never had to do this before our upgrade to 6.6.3.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 16:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288099#M10939</guid>
      <dc:creator>richarddicaire</dc:creator>
      <dc:date>2018-01-05T16:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288100#M10940</link>
      <description>&lt;P&gt;Hi, can anyone provide input as to what is creating &lt;CODE&gt;search_sitedefault_gen*.csv.gz&lt;/CODE&gt; and &lt;CODE&gt;summarize_sitedefault_gen*.csv.gz&lt;/CODE&gt; files in &lt;CODE&gt;/opt/splunk/var/run/splunk/cluster/search-buckets&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 16:40:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288100#M10940</guid>
      <dc:creator>richarddicaire</dc:creator>
      <dc:date>2018-01-08T16:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288101#M10941</link>
      <description>&lt;P&gt;Same issue here on v6.6.5. Did you ever find anything out?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 21:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288101#M10941</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2018-06-25T21:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288102#M10942</link>
      <description>&lt;P&gt;You have a lot of traffic for your deployment. Increase disk space.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 03:12:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288102#M10942</guid>
      <dc:creator>davpx</dc:creator>
      <dc:date>2019-01-26T03:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288103#M10943</link>
      <description>&lt;P&gt;This is NOT a helpful answer and does not explain why there are so many of these files in this directory path.  There apparently is no documentation from Splunk on this. I am opening a case as I suggest everyone else having this does the same. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Feb 2019 15:30:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288103#M10943</guid>
      <dc:creator>BainM</dc:creator>
      <dc:date>2019-02-25T15:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288104#M10944</link>
      <description>&lt;P&gt;This was a combination of two bugs that were fixed in later versions of splunk (7.0.8+, 7.1.6+, 7.2.4+)&lt;/P&gt;

&lt;P&gt;For a workaround, its safe to&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;delete older generation files, keeping the last 10 or so per site&lt;/LI&gt;
&lt;LI&gt;don't delete the gen0 file&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;for example, if i have:&lt;BR /&gt;
search_sitedefault_gen1000.csv.gz as the latest file, i can delete search_sitedefault_gen(1-990).csv.gz safely&lt;/P&gt;

&lt;P&gt;but remember this is per site, so if i have the latest:&lt;/P&gt;

&lt;P&gt;search_site0_gen1000.csv.gz (delete gen1-990 for site0, dont delete gen0)&lt;BR /&gt;
search_site1_gen3500.csv.gz (delete gen1-3490 for site1, dont delete gen0)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288104#M10944</guid>
      <dc:creator>dxu_splunk</dc:creator>
      <dc:date>2020-09-29T23:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288105#M10945</link>
      <description>&lt;P&gt;Hi dxu,&lt;/P&gt;

&lt;P&gt;Is there a workaround for the same?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Santhosh&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 05:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288105#M10945</guid>
      <dc:creator>santu27487kanna</dc:creator>
      <dc:date>2019-10-10T05:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288106#M10946</link>
      <description>&lt;P&gt;FWIW and I know it's not ideal but a rolling restart of the cluster peers will clear these down.  I'm on 7.1.5.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 10:35:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288106#M10946</guid>
      <dc:creator>stepheneardley</dc:creator>
      <dc:date>2019-11-05T10:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288107#M10947</link>
      <description>&lt;P&gt;Thank you stepheneardley.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 10:43:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288107#M10947</guid>
      <dc:creator>santu27487kanna</dc:creator>
      <dc:date>2019-11-05T10:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288108#M10948</link>
      <description>&lt;P&gt;What is the purpose of the file?&lt;BR /&gt;
And do you know if there is a cycle or setting method to delete automatically?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2020 23:56:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/288108#M10948</guid>
      <dc:creator>jk01571</dc:creator>
      <dc:date>2020-01-07T23:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: why is /opt/splunk/var/run/splunk/cluster/search-buckets filling up my disk?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/591646#M25479</link>
      <description>&lt;P&gt;Anyone else facing same issues in 8.2.4. Will check with support and see.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 01:33:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Why-is-opt-splunk-var-run-splunk-cluster-search-buckets-filling/m-p/591646#M25479</guid>
      <dc:creator>Sahr_Lebbie</dc:creator>
      <dc:date>2022-03-31T01:33:40Z</dc:date>
    </item>
  </channel>
</rss>

