<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I figure out why my lastlog directory is huge? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-figure-out-why-my-lastlog-directory-is-huge/m-p/353917#M166519</link>
    <description>&lt;P&gt;The file should not be that big. Period.&lt;/P&gt;

&lt;P&gt;You can't reduce the size without deleting all the data. If you want to delete all the data, don't delete the file, because your system will keep it open and it will stay the same size until you reboot. You can delete the contents of the file with the following command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cp /dev/null &amp;gt;/var/log/lastlog
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 07 Aug 2017 21:21:48 GMT</pubDate>
    <dc:creator>cpetterborg</dc:creator>
    <dc:date>2017-08-07T21:21:48Z</dc:date>
    <item>
      <title>How can I figure out why my lastlog directory is huge?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-figure-out-why-my-lastlog-directory-is-huge/m-p/353916#M166518</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;Why is my lastlog directory so huge?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;-rw-r--r--. 1 root   root   **216G** Aug  7 17:35 lastlog
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What can I do to reduce it?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2017 20:38:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-figure-out-why-my-lastlog-directory-is-huge/m-p/353916#M166518</guid>
      <dc:creator>wvalente</dc:creator>
      <dc:date>2017-08-07T20:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can I figure out why my lastlog directory is huge?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-figure-out-why-my-lastlog-directory-is-huge/m-p/353917#M166519</link>
      <description>&lt;P&gt;The file should not be that big. Period.&lt;/P&gt;

&lt;P&gt;You can't reduce the size without deleting all the data. If you want to delete all the data, don't delete the file, because your system will keep it open and it will stay the same size until you reboot. You can delete the contents of the file with the following command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cp /dev/null &amp;gt;/var/log/lastlog
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 07 Aug 2017 21:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-figure-out-why-my-lastlog-directory-is-huge/m-p/353917#M166519</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-08-07T21:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: How can I figure out why my lastlog directory is huge?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-figure-out-why-my-lastlog-directory-is-huge/m-p/353918#M166520</link>
      <description>&lt;P&gt;I believe that lastlog is a sparse file see &lt;A href="http://www.noah.org/wiki/Lastlog_is_gigantic"&gt;http://www.noah.org/wiki/Lastlog_is_gigantic&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 09:41:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-figure-out-why-my-lastlog-directory-is-huge/m-p/353918#M166520</guid>
      <dc:creator>dshakespeare_sp</dc:creator>
      <dc:date>2017-08-08T09:41:53Z</dc:date>
    </item>
  </channel>
</rss>

