<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to run Security Posture in the Splunk Cloud sandbox with error &amp;quot;The minimum free disk space (2000MB) reached&amp;quot;? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218478#M1307</link>
    <description>&lt;P&gt;Ahh 2p, that's right! &lt;/P&gt;</description>
    <pubDate>Wed, 10 Aug 2016 01:24:27 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2016-08-10T01:24:27Z</dc:date>
    <item>
      <title>Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218471#M1300</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;Search not executed: The minimum free disk space (2000MB) reached for /opt/splunk/var/run/splunk/dispatch. user=wtaddis. 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk Version&lt;BR /&gt;
6.3.1511&lt;/P&gt;

&lt;P&gt;Splunk Build&lt;BR /&gt;
8effae892620 &lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 18:00:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218471#M1300</guid>
      <dc:creator>wtaddis</dc:creator>
      <dc:date>2016-08-08T18:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218472#M1301</link>
      <description>&lt;P&gt;This is for a Splunk Enterprise Security Workshop&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 18:11:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218472#M1301</guid>
      <dc:creator>wtaddis</dc:creator>
      <dc:date>2016-08-08T18:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218473#M1302</link>
      <description>&lt;P&gt;This could mean that your dispatch folder is "full" which will prevent you from doing any searches. This became full because too many searches we're going on in parallel and you don't have enough room on the file system. You can manually clear these files without any harm, this will just kill the search&lt;/P&gt;

&lt;P&gt;Or this means that your &lt;CODE&gt;opt&lt;/CODE&gt; drive is full. Most likely your coldb is retaining a lot of old files and not moving them to the frozen bucket. Go to &lt;CODE&gt;/opt/splunk/var/lib/splunk/_internaldb&lt;/CODE&gt; and do a &lt;CODE&gt;du -sh *&lt;/CODE&gt; and see what is taking up space &lt;/P&gt;

&lt;P&gt;You could also go into the config file and decrease the file size needed which will temporarily fix your problem, but you will have the same issue again very quickly. This is in &lt;CODE&gt;server.conf&lt;/CODE&gt; under the &lt;CODE&gt;[diskUsage]&lt;/CODE&gt; stanza.. It should be like &lt;CODE&gt;minFreeSpace =xx&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Go look in your db and see what files are taking lots of room and delete some. You should then go to your &lt;CODE&gt;settings/indexes&lt;/CODE&gt; and set a max size for your cold bucket to prevent this in the future. &lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 18:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218473#M1302</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-08-08T18:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218474#M1303</link>
      <description>&lt;P&gt;Thanks. Since this is a Splunk Enterprise Security Workshop located in the Splunk Cloud  would the configuration take place in Splunk's  infrastrucure.? Thanks again.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 18:41:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218474#M1303</guid>
      <dc:creator>wtaddis</dc:creator>
      <dc:date>2016-08-08T18:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218475#M1304</link>
      <description>&lt;P&gt;I also want to describe what the dispatch folder does for more clarity.. &lt;/P&gt;

&lt;P&gt;The dispatch dir will house "artifacts" and these searches will be "cached" in the dispatch directory so you can load up searches faster. I believe the scheduled searches are relative to the timespan of the search, so if you have a long timespan then this will live in the dispatch folder for a longer period of time (Could be days). So to sum it up, if you have a lot of scheduled searches AND they have a big timespan specified, then this will quickly clog up your dispatch folder. So you will need to increase the size, decrease the amount of scheduled searches, decrease the timespan in those scheduled searches or decrease the minimum free disk space &lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 19:02:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218475#M1304</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-08-08T19:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218476#M1305</link>
      <description>&lt;P&gt;Yes on the indexer&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 19:11:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218476#M1305</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-08-08T19:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218477#M1306</link>
      <description>&lt;P&gt;Here's an answer from a previous post on this topic for further reading &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/213571/what-causes-too-many-search-jobs-found-in-the-disp.html#answer-421843"&gt;https://answers.splunk.com/answers/213571/what-causes-too-many-search-jobs-found-in-the-disp.html#answer-421843&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 00:32:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218477#M1306</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2016-08-10T00:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to run Security Posture in the Splunk Cloud sandbox with error "The minimum free disk space (2000MB) reached"?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218478#M1307</link>
      <description>&lt;P&gt;Ahh 2p, that's right! &lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 01:24:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Unable-to-run-Security-Posture-in-the-Splunk-Cloud-sandbox-with/m-p/218478#M1307</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-08-10T01:24:27Z</dc:date>
    </item>
  </channel>
</rss>

