<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the Splunk dispatch directory not getting cleaned up automatically, even after setting the dispatch.ttl in savedsearches.conf? in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243015#M4864</link>
    <description>&lt;P&gt;Last time this happened to me there was another error causing the problem.&lt;/P&gt;

&lt;P&gt;Please check index=_internal for any ERROR or WARN messages, and then fix all of them you can.  In my case i had a datamodel that was deleted incorrectly and splunk was pounding the logs with "data model not found" errors.  AND my issue completely disabled all scheduled searches, alerts, reports, and the sendemail command.  After removing the saved search that referenced the missing data model, 10000 emails went out, performance increased, and the problems went away.&lt;/P&gt;

&lt;P&gt;The issue was that Splunk was trying so hard to find the data model, it couldnt do anything else... all the maintenance tasks like emptying the old/obsolete search bundles were failing to execute because "splunk" was too busy.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jan 2016 13:48:47 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2016-01-01T13:48:47Z</dc:date>
    <item>
      <title>Why is the Splunk dispatch directory not getting cleaned up automatically, even after setting the dispatch.ttl in savedsearches.conf?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243013#M4862</link>
      <description>&lt;P&gt;We run into some issues in our Splunk environment.&lt;BR /&gt;
We have a Splunk 6.3 indexer and search head. The dispatch directory on the search head is constantly growing and Splunk stops working after a few days. We then need to manually restart the search head. &lt;BR /&gt;
After the restart, the dispatch directory is getting cleaned up automatically and only searches from the last 24h remain.&lt;BR /&gt;
I already set the dispatch.ttl in savedsearches.conf to 86400. (1 day) But the artifacts in the directory remain for much longer until we restart the system.&lt;/P&gt;

&lt;P&gt;We have about 10 scheduled searches with alarms which run every hour, so it is not that much. &lt;BR /&gt;
Is there any way to fix the automatic clean-up of the directory or what is the best way to restart the search head automatically every night on a Windows system?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2015 09:45:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243013#M4862</guid>
      <dc:creator>Plotkowski</dc:creator>
      <dc:date>2015-11-23T09:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk dispatch directory not getting cleaned up automatically, even after setting the dispatch.ttl in savedsearches.conf?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243014#M4863</link>
      <description>&lt;P&gt;I'm having the same problem as well.. Will have to setup a .bat to clear out until solution is provided.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Dec 2015 20:31:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243014#M4863</guid>
      <dc:creator>jrubio1</dc:creator>
      <dc:date>2015-12-30T20:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk dispatch directory not getting cleaned up automatically, even after setting the dispatch.ttl in savedsearches.conf?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243015#M4864</link>
      <description>&lt;P&gt;Last time this happened to me there was another error causing the problem.&lt;/P&gt;

&lt;P&gt;Please check index=_internal for any ERROR or WARN messages, and then fix all of them you can.  In my case i had a datamodel that was deleted incorrectly and splunk was pounding the logs with "data model not found" errors.  AND my issue completely disabled all scheduled searches, alerts, reports, and the sendemail command.  After removing the saved search that referenced the missing data model, 10000 emails went out, performance increased, and the problems went away.&lt;/P&gt;

&lt;P&gt;The issue was that Splunk was trying so hard to find the data model, it couldnt do anything else... all the maintenance tasks like emptying the old/obsolete search bundles were failing to execute because "splunk" was too busy.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2016 13:48:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243015#M4864</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-01-01T13:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk dispatch directory not getting cleaned up automatically, even after setting the dispatch.ttl in savedsearches.conf?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243016#M4865</link>
      <description>&lt;P&gt;ahhh I've seen some errors.. I'll look into cleaning that up and report back.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 20:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243016#M4865</guid>
      <dc:creator>jrubio1</dc:creator>
      <dc:date>2016-01-14T20:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Splunk dispatch directory not getting cleaned up automatically, even after setting the dispatch.ttl in savedsearches.conf?</title>
      <link>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243017#M4866</link>
      <description>&lt;P&gt;I would be suspicious of anything that could hold up a scheduler... Missing searches, data models, infinite loop conditions, extremely long running searches, broken servers missing punctuation in conf files, etc.  Good news is you have the best tool for finding needles in haystacks!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 02:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Why-is-the-Splunk-dispatch-directory-not-getting-cleaned-up/m-p/243017#M4866</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2016-01-15T02:03:07Z</dc:date>
    </item>
  </channel>
</rss>

