<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The index processor has paused data flow in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/The-index-processor-has-paused-data-flow/m-p/523748#M4563</link>
    <description>&lt;P&gt;After a hardware failure was resolved, I attempted to start splunk again...but I am now getting this error&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"The index processor has paused data flow. Current free disk space on partition '/' has fallen to 158MB, below the minimum of 5000MB. Data writes to index path '/data1/splunk/indexes/audit/db'cannot safely proceed. Increase free disk space on partition '/' by removing or relocating data."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I understand what is saying, but the odd part is that partition "/" never had that much space and all other indexers are configured the same with no issues.&lt;/P&gt;&lt;P&gt;What am I missing here?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2020 16:25:25 GMT</pubDate>
    <dc:creator>rgarcia</dc:creator>
    <dc:date>2020-10-08T16:25:25Z</dc:date>
    <item>
      <title>The index processor has paused data flow</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/The-index-processor-has-paused-data-flow/m-p/523748#M4563</link>
      <description>&lt;P&gt;After a hardware failure was resolved, I attempted to start splunk again...but I am now getting this error&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"The index processor has paused data flow. Current free disk space on partition '/' has fallen to 158MB, below the minimum of 5000MB. Data writes to index path '/data1/splunk/indexes/audit/db'cannot safely proceed. Increase free disk space on partition '/' by removing or relocating data."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I understand what is saying, but the odd part is that partition "/" never had that much space and all other indexers are configured the same with no issues.&lt;/P&gt;&lt;P&gt;What am I missing here?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 16:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/The-index-processor-has-paused-data-flow/m-p/523748#M4563</guid>
      <dc:creator>rgarcia</dc:creator>
      <dc:date>2020-10-08T16:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: The index processor has paused data flow</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/The-index-processor-has-paused-data-flow/m-p/523749#M4564</link>
      <description>&lt;P&gt;Can it be so that your node hasn’t mount all FSs yet?&lt;/P&gt;&lt;P&gt;You should check what is your SPLUNK_DB path and then check that it’s present and it has enough space.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 16:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/The-index-processor-has-paused-data-flow/m-p/523749#M4564</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-08T16:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: The index processor has paused data flow</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/The-index-processor-has-paused-data-flow/m-p/523775#M4565</link>
      <description>&lt;P&gt;You're right, mount points were missing. thank you&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 18:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/The-index-processor-has-paused-data-flow/m-p/523775#M4565</guid>
      <dc:creator>rgarcia</dc:creator>
      <dc:date>2020-10-08T18:08:25Z</dc:date>
    </item>
  </channel>
</rss>

