<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FULL STORAGE IN Deployment Server in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/FULL-STORAGE-IN-Deployment-Server/m-p/693865#M12024</link>
    <description>&lt;P&gt;The specs listed are the *minimums* specified by Splunk.&amp;nbsp; What the *actual* specs of the DS?&amp;nbsp; Which version of Splunk is the DS running?&amp;nbsp; How many apps are in the deployment-apps directory?&lt;/P&gt;&lt;P&gt;Splunk does not use /root to store anything and Best Practice is to put $SPLUNK_HOME and $SPLUNK_DB in separate mount points not shared with the OS.&lt;/P&gt;&lt;P&gt;Have you run &lt;FONT face="courier new,courier"&gt;du&lt;/FONT&gt; to see what files/directories are using the most storage?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2024 15:01:32 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-07-19T15:01:32Z</dc:date>
    <item>
      <title>FULL STORAGE IN Deployment Server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/FULL-STORAGE-IN-Deployment-Server/m-p/693842#M12023</link>
      <description>&lt;P&gt;I am wondering why Deployment Server is full and the only stored in this server is Deployment Server Ta’s and .Conf to distribute the TA’s and Conf to Universal Forwarders.&lt;/P&gt;&lt;P&gt;this is the Specs.&lt;/P&gt;&lt;P&gt;Deployment Server&lt;/P&gt;&lt;P&gt;- 16 CPU Core (or 32 vCPU – if VM then must be dedicated), 2 GHz+ per core or greater&lt;BR /&gt;- 16GB RAM&lt;BR /&gt;- 1 x 200GB storage space (for OS and Splunk)&lt;BR /&gt;- 64-bits OS Linux/Windows&lt;BR /&gt;- 10GB Ethernet NIC, with optional 2nd NIC for management network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but the disk Space is full in /root&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 10:03:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/FULL-STORAGE-IN-Deployment-Server/m-p/693842#M12023</guid>
      <dc:creator>Unnamed16</dc:creator>
      <dc:date>2024-07-19T10:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: FULL STORAGE IN Deployment Server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/FULL-STORAGE-IN-Deployment-Server/m-p/693865#M12024</link>
      <description>&lt;P&gt;The specs listed are the *minimums* specified by Splunk.&amp;nbsp; What the *actual* specs of the DS?&amp;nbsp; Which version of Splunk is the DS running?&amp;nbsp; How many apps are in the deployment-apps directory?&lt;/P&gt;&lt;P&gt;Splunk does not use /root to store anything and Best Practice is to put $SPLUNK_HOME and $SPLUNK_DB in separate mount points not shared with the OS.&lt;/P&gt;&lt;P&gt;Have you run &lt;FONT face="courier new,courier"&gt;du&lt;/FONT&gt; to see what files/directories are using the most storage?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 15:01:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/FULL-STORAGE-IN-Deployment-Server/m-p/693865#M12024</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-07-19T15:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: FULL STORAGE IN Deployment Server</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/FULL-STORAGE-IN-Deployment-Server/m-p/693935#M12025</link>
      <description>&lt;P&gt;Hi Rich, thank you for your info ill check this and ill be back to you&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 07:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/FULL-STORAGE-IN-Deployment-Server/m-p/693935#M12025</guid>
      <dc:creator>Unnamed16</dc:creator>
      <dc:date>2024-07-22T07:48:06Z</dc:date>
    </item>
  </channel>
</rss>

