<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk indexer server run out of memory in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-server-run-out-of-memory/m-p/504153#M85955</link>
    <description>&lt;P&gt;Your problem is disk space, not memory.&amp;nbsp; Well, you may also have a memory problem, but the evidence in your posting screams disk space.&lt;/P&gt;&lt;P&gt;A related problem is Splunk and the operating system are sharing a file system (/).&amp;nbsp; This can become an issue when Splunk uses up disk space and prevents the OS from doing any work.&amp;nbsp; This is not called out in Splunk docs, but is a basic Linux admin matter.&amp;nbsp; /, $SPLUNK_HOME, and $SPLUNK_DB should be separate file systems.&lt;/P&gt;&lt;P&gt;Don't touch anything in /opt/splunk/var/lib/splunk.&amp;nbsp; That's where your data is stored and you risk data loss by manipulating files there.&lt;/P&gt;&lt;P&gt;You can safely delete files in /opt/splunk/var/log/splunk having names that end with a digit.&lt;/P&gt;&lt;P&gt;You really have two options: 1) add more storage; or 2) use the frozenTimePeriodInSeconds setting in indexes.conf to reduce the retention time of your indexed data.&amp;nbsp; I recommend the former.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jun 2020 13:12:36 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-06-12T13:12:36Z</dc:date>
    <item>
      <title>Splunk indexer server run out of memory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-server-run-out-of-memory/m-p/503901#M85934</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;My splunk indexer server are running out if memory, its main reason are&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/var/run/searchpeers&lt;BR /&gt;/opt/splunk/var/lib/splunk/_introspection&lt;BR /&gt;/opt/splunk/var/lib/splunk/_internaldb&lt;BR /&gt;/opt/splunk/var/lib/splunk/kvstore&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="arun_kant_sharm_1-1591875437534.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9126i190924740FACC87D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="arun_kant_sharm_1-1591875437534.png" alt="arun_kant_sharm_1-1591875437534.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Indexer&amp;nbsp;_introspection, _internaldb,&amp;nbsp; kvstore have default setting, its data are not move in cold and frozen bucket.&lt;/P&gt;&lt;P&gt;Please suggest what can I do to create space at my server ?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 11:45:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-server-run-out-of-memory/m-p/503901#M85934</guid>
      <dc:creator>arun_kant_sharm</dc:creator>
      <dc:date>2020-06-11T11:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer server run out of memory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-server-run-out-of-memory/m-p/504140#M85952</link>
      <description>&lt;P&gt;Your question is big vague&lt;/P&gt;&lt;P&gt;- Are you running out of memory or Disk space? the screenshot seems to show problem with disk-space&lt;/P&gt;&lt;P&gt;- Indexer needs quite lot of memory for powerful systems or large data. What's your spec for memory? How much RAM?&lt;/P&gt;&lt;P&gt;- What's your indexes.conf specifications (run a btool and put the output in your Question, so people could understand the issues)&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 12:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-server-run-out-of-memory/m-p/504140#M85952</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2020-06-12T12:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk indexer server run out of memory</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-server-run-out-of-memory/m-p/504153#M85955</link>
      <description>&lt;P&gt;Your problem is disk space, not memory.&amp;nbsp; Well, you may also have a memory problem, but the evidence in your posting screams disk space.&lt;/P&gt;&lt;P&gt;A related problem is Splunk and the operating system are sharing a file system (/).&amp;nbsp; This can become an issue when Splunk uses up disk space and prevents the OS from doing any work.&amp;nbsp; This is not called out in Splunk docs, but is a basic Linux admin matter.&amp;nbsp; /, $SPLUNK_HOME, and $SPLUNK_DB should be separate file systems.&lt;/P&gt;&lt;P&gt;Don't touch anything in /opt/splunk/var/lib/splunk.&amp;nbsp; That's where your data is stored and you risk data loss by manipulating files there.&lt;/P&gt;&lt;P&gt;You can safely delete files in /opt/splunk/var/log/splunk having names that end with a digit.&lt;/P&gt;&lt;P&gt;You really have two options: 1) add more storage; or 2) use the frozenTimePeriodInSeconds setting in indexes.conf to reduce the retention time of your indexed data.&amp;nbsp; I recommend the former.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 13:12:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-indexer-server-run-out-of-memory/m-p/504153#M85955</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-12T13:12:36Z</dc:date>
    </item>
  </channel>
</rss>

