<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disk space on /opt/splunk below the minimum of 5000MB in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Disk-space-on-opt-splunk-below-the-minimum-of-5000MB/m-p/356488#M19624</link>
    <description>&lt;P&gt;The _internal index contains Splunk log files like splunkd.log.  Deleting _internal buckets has no effect on your production data, but it may make it more difficult to troubleshoot problems.  &lt;/P&gt;

&lt;P&gt;Also, while the log may say Splunk won't write to _internal, that doesn't mean _internal is the cause of the problem.  Review all of the usage of that disk to see what is consuming it.  If there are non-Splunk applications writing to the same space, try to separate them.  Review the retention policies of your indexes to see if you are storing more data than necessary.  If so, changing your indexes.conf settings can reduce the amount of space used.&lt;/P&gt;

&lt;P&gt;Since this happens often, consider moving $SPLUNK_DB to larger storage, preferably separate from $SPLUNK_HOME.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 18:31:17 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-09-29T18:31:17Z</dc:date>
    <item>
      <title>Disk space on /opt/splunk below the minimum of 5000MB</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Disk-space-on-opt-splunk-below-the-minimum-of-5000MB/m-p/356486#M19622</link>
      <description>&lt;P&gt;In my production environment, I have around 4 Splunk environments.&lt;BR /&gt;
I keep observing every alternate day, in splunk web console, I get the below error. Obviously, my next move is to delete the warm dbs something like this "db_1520234296_1519816201_101" from the below path to free up the space.&lt;/P&gt;

&lt;P&gt;'/opt/splunk/indexer/var/lib/splunk/_internaldb/db&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Search peer server has the following message: Disk Monitor: The index processor has paused data flow.Current free disk space on &lt;BR /&gt;
partition '/opt/splunk' has fallen to 4988MB, below the minimum of 5000MB.Data writes to index path '/opt/splunk/indexer/var/lib/splunk/_internaldb/db can't safely proceed. Increase free disk space on partition '/opt/splunk' by removing or relocating data.&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;I would like to understand, what is the impact to my production data if i delete this logs and what type of data does this _internaldb logs contain. Can someone explain me on this. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:31:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Disk-space-on-opt-splunk-below-the-minimum-of-5000MB/m-p/356486#M19622</guid>
      <dc:creator>rchittip</dc:creator>
      <dc:date>2020-09-29T18:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Disk space on /opt/splunk below the minimum of 5000MB</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Disk-space-on-opt-splunk-below-the-minimum-of-5000MB/m-p/356487#M19623</link>
      <description>&lt;P&gt;Well although it is not your own ingested data, the impact is you can't debug actions and assure accountability of what users have been doing&lt;/P&gt;

&lt;P&gt;That is quite a security issue you have in case you need to justify or figure out internal sequence of events &lt;/P&gt;

&lt;P&gt;You are unconsciously covering tracks &lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 13:29:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Disk-space-on-opt-splunk-below-the-minimum-of-5000MB/m-p/356487#M19623</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2018-03-16T13:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Disk space on /opt/splunk below the minimum of 5000MB</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Disk-space-on-opt-splunk-below-the-minimum-of-5000MB/m-p/356488#M19624</link>
      <description>&lt;P&gt;The _internal index contains Splunk log files like splunkd.log.  Deleting _internal buckets has no effect on your production data, but it may make it more difficult to troubleshoot problems.  &lt;/P&gt;

&lt;P&gt;Also, while the log may say Splunk won't write to _internal, that doesn't mean _internal is the cause of the problem.  Review all of the usage of that disk to see what is consuming it.  If there are non-Splunk applications writing to the same space, try to separate them.  Review the retention policies of your indexes to see if you are storing more data than necessary.  If so, changing your indexes.conf settings can reduce the amount of space used.&lt;/P&gt;

&lt;P&gt;Since this happens often, consider moving $SPLUNK_DB to larger storage, preferably separate from $SPLUNK_HOME.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:31:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Disk-space-on-opt-splunk-below-the-minimum-of-5000MB/m-p/356488#M19624</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-29T18:31:17Z</dc:date>
    </item>
  </channel>
</rss>

