<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High disk space utilization on indexer in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/506901#M4306</link>
    <description>&lt;P&gt;The temp index may be defined in a different indexes.conf file.&amp;nbsp; Try this command to find it.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool --debug indexes list temp&lt;/LI-CODE&gt;&lt;P&gt;Or run this search from the GUI&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /services/data/indexes | dedup title | table title&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jul 2020 16:40:20 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-07-01T16:40:20Z</dc:date>
    <item>
      <title>High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/503930#M4211</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have disk space issue with indexer. where there is 92% utilization in opt/splunkdata dir.&amp;nbsp; and most space consuming files in this directory are db files, such as "_internal_db" and some other temp folders, which also contain dbs. I'm not sure which of them to clear. Almost all files in directory are db.&amp;nbsp;&lt;/P&gt;&lt;P&gt;could please suggest want kind of data can deleted to free some space without loosing important data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 13:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/503930#M4211</guid>
      <dc:creator>Reethika</dc:creator>
      <dc:date>2020-06-11T13:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/503933#M4212</link>
      <description>Everything in /opt/splunkdata is important data. Don't touch any of it.&lt;BR /&gt;Either add storage to the indexer or reduce the amount of data you retain in your indexes.</description>
      <pubDate>Thu, 11 Jun 2020 14:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/503933#M4212</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-11T14:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504186#M4225</link>
      <description>&lt;P&gt;Thankyou &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt; .&lt;/P&gt;&lt;P&gt;/opt/splunkdata have "temp" directory, which consumes most data. cleaning this directory is suggested?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 15:35:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504186#M4225</guid>
      <dc:creator>Reethika</dc:creator>
      <dc:date>2020-06-12T15:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504196#M4228</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222223"&gt;@Reethika&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;enlarge the storage (as suggested by &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;) is always the best solution.&lt;/P&gt;&lt;P&gt;If you cannot do this, you could also reduce the disk occupation of _internal data reducing the retention on this Index: instead of one month set e.g. 15 days:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;open indexes.conf in $SPLUNK_HOME/etc/system/local, if you haven't it, create it and copy the _internal stanza from the default folder.&lt;/LI&gt;&lt;LI&gt;modify the parameter&amp;nbsp;FrozenTimePeriodInSecs&lt;SPAN&gt;&amp;nbsp; = 1296000,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;restart Splunk.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;In this way the disk occupation of this index will be reduced.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2020 16:05:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504196#M4228</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-12T16:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504254#M4233</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; .&lt;/P&gt;&lt;P&gt;As suggested, data retention period is reduced for internal index.&lt;/P&gt;&lt;P&gt;But the utilization is same.&lt;/P&gt;&lt;P&gt;New &amp;nbsp;FrozenTimePeriodInSecs&amp;nbsp; parameter is applicable only&amp;nbsp; future to be indexed data. And old index data would be same.&lt;/P&gt;&lt;P&gt;Please can you clear this out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jun 2020 04:10:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504254#M4233</guid>
      <dc:creator>Reethika</dc:creator>
      <dc:date>2020-06-13T04:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504266#M4235</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222223"&gt;@Reethika&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;retention is appliad on the full index, so if you reduce the retention of an index from 30 to 15 days, also the space on disk will be reduces, the question is: before retention reduction, had you events older than 15 days?&lt;/P&gt;&lt;P&gt;if yes, they will be deleted, if not obviously there wasn't any reduction.&lt;/P&gt;&lt;P&gt;In addition, remember that events deletion in Splunk is made at bucket level, in other words, events are stored in buckets, when the earliest event of a bucket exceed the retention period, all the bucket will be deleted, for this reason you could have events older than the retention period.&lt;/P&gt;&lt;P&gt;Anyway, check the disk occupation after few minutes and, if you had many events older than the retention period, the free disk space will be more than before.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jun 2020 10:27:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504266#M4235</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-13T10:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504423#M4237</link>
      <description>I don't recall ever seeing a 'temp' directory in $SPLUNK_DB. What's in it?</description>
      <pubDate>Mon, 15 Jun 2020 12:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504423#M4237</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-06-15T12:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504782#M4238</link>
      <description>&lt;P class="lia-align-left"&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt; ,&lt;/P&gt;&lt;P class="lia-align-left"&gt;So In my case, I have reduced retention period from 1 year to 3 months for an index. And after restarting splunk, its still the same. and after a day the utilization have increased.&lt;/P&gt;&lt;P class="lia-align-left"&gt;In my scenario, /opt/splunkdata/temp/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; filepath,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;db&lt;/LI&gt;&lt;LI&gt;datamodel&lt;/LI&gt;&lt;LI&gt;summary&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;are present in /temp.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 12:26:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504782#M4238</guid>
      <dc:creator>Reethika</dc:creator>
      <dc:date>2020-06-17T12:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504786#M4239</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/222223"&gt;@Reethika&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;temp seems to be an index, do you see it in the indexes.conf or in web interface?&lt;/P&gt;&lt;P&gt;If it's an index, see if you can reduce retention on this index.&lt;/P&gt;&lt;P&gt;If it isn't an index, see which data go in it, maybe there's a script or other.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 12:35:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/504786#M4239</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-06-17T12:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/506893#M4305</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;temp &lt;/SPAN&gt;"its an index, can't find it on web interface though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;cat /opt/splunk/etc/apps/Axxxxxxxxxxxxxxxxxxxx/default/indexes.conf&lt;BR /&gt;[_internal]&lt;BR /&gt;maxTotalDataSizeMB = 70000&lt;BR /&gt;homePath.maxDataSizeMB = 10000&lt;BR /&gt;homePath = $SPLUNK_DB/_internaldb/db&lt;BR /&gt;coldPath.maxDataSizeMB = 60000&lt;BR /&gt;coldPath = $SPLUNK_DB/_internaldb/colddb&lt;BR /&gt;thawedPath = $SPLUNK_DB/_internaldb/thaweddb&lt;BR /&gt;frozenTimePeriodInSecs = 7776000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are parameters used, and restarted. but didn't work.&lt;/P&gt;&lt;P&gt;earlier f&lt;SPAN&gt;rozenTimePeriodInSecs&lt;/SPAN&gt; was about an year.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;coldPath.maxDataSizeMB&lt;/SPAN&gt; &amp;gt;&amp;nbsp;&lt;SPAN&gt;frozenTimePeriodInSecs &lt;/SPAN&gt;?&amp;nbsp;&lt;/P&gt;&lt;P&gt;maxDataSizeMB rules over&amp;nbsp;frozenTimePeriodInSecs ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reducing&amp;nbsp;&lt;SPAN&gt;coldPath.maxDataSizeMB&lt;/SPAN&gt; can help?&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 15:21:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/506893#M4305</guid>
      <dc:creator>Reethika</dc:creator>
      <dc:date>2020-07-01T15:21:36Z</dc:date>
    </item>
    <item>
      <title>Re: High disk space utilization on indexer</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/506901#M4306</link>
      <description>&lt;P&gt;The temp index may be defined in a different indexes.conf file.&amp;nbsp; Try this command to find it.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool --debug indexes list temp&lt;/LI-CODE&gt;&lt;P&gt;Or run this search from the GUI&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rest /services/data/indexes | dedup title | table title&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 16:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/High-disk-space-utilization-on-indexer/m-p/506901#M4306</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-01T16:40:20Z</dc:date>
    </item>
  </channel>
</rss>

