<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are the bundles present in /opt/splunk/var/run/searchpeers location in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147583#M1706</link>
    <description>&lt;P&gt;Thanks MuS. That helped but one more query.there are multiple bundles for same search head. Do you have any idea why these many copies are being stored. Cant we have only latest copy and delete the old bundles?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2013 10:43:57 GMT</pubDate>
    <dc:creator>adityapavan18</dc:creator>
    <dc:date>2013-11-19T10:43:57Z</dc:date>
    <item>
      <title>What are the bundles present in /opt/splunk/var/run/searchpeers location</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147581#M1704</link>
      <description>&lt;P&gt;Could anyone please tell me whatare all the bundles present in  /opt/splunk/var/run/searchpeers location.&lt;/P&gt;

&lt;P&gt;This location is kind of holding lot of data and disk space is almost full.&lt;/P&gt;

&lt;P&gt;From what i saw this location is holding configurations of all the search heads contacting this indexer.&lt;/P&gt;

&lt;P&gt;But for each search head there are around 5 copies of bundles with different timestamps&lt;/P&gt;

&lt;P&gt;SearchHead1-1384788323          Mon, 18 Nov 2013 15:25:23 GMT &lt;/P&gt;

&lt;P&gt;SearchHead1-1384796779          Mon, 18 Nov 2013 17:46:19 GMT &lt;/P&gt;

&lt;P&gt;SearchHead1-1384810416          Mon, 18 Nov 2013 21:33:36 GMT &lt;/P&gt;

&lt;P&gt;SearchHead1-1384810689          Mon, 18 Nov 2013 21:38:09 GMT &lt;/P&gt;

&lt;P&gt;SearchHead1-1384811445          Mon, 18 Nov 2013 21:50:45 GMT&lt;/P&gt;

&lt;P&gt;Is there a way i can restrict these many number of copies and let only the latest be present.&lt;/P&gt;

&lt;P&gt;Or any other option to restrict this please let me know&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2013 10:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147581#M1704</guid>
      <dc:creator>adityapavan18</dc:creator>
      <dc:date>2013-11-19T10:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: What are the bundles present in /opt/splunk/var/run/searchpeers location</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147582#M1705</link>
      <description>&lt;P&gt;Hi adityapavan18,&lt;/P&gt;

&lt;P&gt;you can find all the information in the docs &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Whatisdistributedsearch#What_search_heads_send_to_search_peers"&gt;abount what search heads send to search peers&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2013 10:32:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147582#M1705</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-11-19T10:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: What are the bundles present in /opt/splunk/var/run/searchpeers location</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147583#M1706</link>
      <description>&lt;P&gt;Thanks MuS. That helped but one more query.there are multiple bundles for same search head. Do you have any idea why these many copies are being stored. Cant we have only latest copy and delete the old bundles?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2013 10:43:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147583#M1706</guid>
      <dc:creator>adityapavan18</dc:creator>
      <dc:date>2013-11-19T10:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: What are the bundles present in /opt/splunk/var/run/searchpeers location</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147584#M1707</link>
      <description>&lt;P&gt;you should not delete bundles unless you want to mess up Splunk. For the moment I cannot tell you if there is a conf option to limit that. If I find something, I'll get back to you.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2013 13:03:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147584#M1707</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-11-19T13:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: What are the bundles present in /opt/splunk/var/run/searchpeers location</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147585#M1708</link>
      <description>&lt;P&gt;As of Aug 16, 2016 - I can't find a way to limit the space. BUT, you &lt;EM&gt;can&lt;/EM&gt; clean up the older bundles. The best thing is to keep the latest bundle (and delta file) for each search head. &lt;/P&gt;

&lt;P&gt;You can make the bundles smaller by disabling apps on the search head that you are not using. For example, I am not using the splunk_archiver app which is enabled by default. Disabling it saves approximately 40MB per bundle - not a lot unless you have many copies of bundles.&lt;/P&gt;

&lt;P&gt;In a really desperate case, you can stop Splunk and then remove the entire $SPLUNK_HOME/var/run/searchpeers directory for the indexer(s), then restart Splunk. Now each search head will have to resend its bundle, but it should recover some space...&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 21:55:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/What-are-the-bundles-present-in-opt-splunk-var-run-searchpeers/m-p/147585#M1708</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-08-16T21:55:25Z</dc:date>
    </item>
  </channel>
</rss>

