<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it safe to delete .bundle files from /opt/splunk/var/run/search peers ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446298#M77615</link>
    <description>&lt;P&gt;size of the single .delta file size is around 1.6 GB.  Can we still delete the .delta file of this size. &lt;/P&gt;</description>
    <pubDate>Tue, 17 Jul 2018 17:01:58 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2018-07-17T17:01:58Z</dc:date>
    <item>
      <title>Is it safe to delete .bundle files from /opt/splunk/var/run/search peers ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446296#M77613</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Currently we have an disk space issue in two of the splunk indexer instances and we have separate volume create for storing the indexed data. We found that /opt/splunk/var/run/search peers is consuming nearly 19 GB of disk space and /opt/splunk/var/lib/ is occupying some where around 15 GB most containing the splunk internal data. &lt;/P&gt;

&lt;P&gt;Total disk space allotted for 47G   41G  4.1G  91% /opt  &lt;/P&gt;

&lt;P&gt;Question : &lt;/P&gt;

&lt;P&gt;1) Is it safe to delete the .bundle files from this  location for the indexer instances.&lt;BR /&gt;
2) What will be the correct solution to prevent the disk crunch issue in future.&lt;/P&gt;

&lt;P&gt;kindly guide me on this. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 16:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446296#M77613</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-07-17T16:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to delete .bundle files from /opt/splunk/var/run/search peers ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446297#M77614</link>
      <description>&lt;P&gt;yes it is safe to delete the bundles. How big are the bundles a piece? &lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 16:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446297#M77614</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2018-07-17T16:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to delete .bundle files from /opt/splunk/var/run/search peers ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446298#M77615</link>
      <description>&lt;P&gt;size of the single .delta file size is around 1.6 GB.  Can we still delete the .delta file of this size. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:01:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446298#M77615</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-07-17T17:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to delete .bundle files from /opt/splunk/var/run/search peers ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446299#M77616</link>
      <description>&lt;P&gt;yes, i would check to make sure you are not unnecessarily replicating apps you don't use and lookups that aren't useful. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 17:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446299#M77616</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2018-07-17T17:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to delete .bundle files from /opt/splunk/var/run/search peers ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446300#M77617</link>
      <description>&lt;P&gt;Hi Carsonza, thanks for your inputs,  I had found the issue we had a .csv with size of 661MB and along with other knowledge bundles and it was causing the replication issue. When checked the lookup file and found that it was broken, because the fields in the lookup table are data that is not relevant to ServiceNow.  On fixing the lookup issue the .csv file size was reduce to 49 MB and it cleared the space issue. &lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 12:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446300#M77617</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-07-27T12:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Is it safe to delete .bundle files from /opt/splunk/var/run/search peers ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446301#M77618</link>
      <description>&lt;P&gt;good to hear, if my answer helped you reach this conclusion please accept my answer. &lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2018 14:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-safe-to-delete-bundle-files-from-opt-splunk-var-run-search/m-p/446301#M77618</guid>
      <dc:creator>CarsonZa</dc:creator>
      <dc:date>2018-07-27T14:43:06Z</dc:date>
    </item>
  </channel>
</rss>

