<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I fix low disk space in Enterprise indexer? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-fix-low-disk-space-in-Enterprise-indexer/m-p/610556#M212346</link>
    <description>&lt;P&gt;How do I fix low disk space in enterprise indexer.&lt;/P&gt;
&lt;P&gt;Please comment back on how to fix.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Aug 2022 23:23:53 GMT</pubDate>
    <dc:creator>Fields29</dc:creator>
    <dc:date>2022-08-23T23:23:53Z</dc:date>
    <item>
      <title>How do I fix low disk space in Enterprise indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-fix-low-disk-space-in-Enterprise-indexer/m-p/610556#M212346</link>
      <description>&lt;P&gt;How do I fix low disk space in enterprise indexer.&lt;/P&gt;
&lt;P&gt;Please comment back on how to fix.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 23:23:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-fix-low-disk-space-in-Enterprise-indexer/m-p/610556#M212346</guid>
      <dc:creator>Fields29</dc:creator>
      <dc:date>2022-08-23T23:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer low disk space</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-fix-low-disk-space-in-Enterprise-indexer/m-p/610560#M212347</link>
      <description>&lt;P&gt;There are two ways: 1) Add more disks; 2) delete some data.&lt;/P&gt;&lt;P&gt;There are many ways to reduce disk space use.&amp;nbsp; If the $SPLUNK_DB space is shared with the OS or $SPLUNK_HOME (both bad ideas) then use the &lt;FONT face="courier new,courier"&gt;du&lt;/FONT&gt; utility to determine what is using up disk space and correct as necessary.&lt;/P&gt;&lt;P&gt;Check for old bundles and delete them.&lt;/P&gt;&lt;P&gt;You'll get the most return, however, by reducing indexed data.&amp;nbsp; Reduce the &lt;FONT face="courier new,courier"&gt;frozenTimePeriodInSecs&lt;/FONT&gt; setting (it defaults to 7 years) for one or more of your indexes and restart the indexer.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 20:55:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-fix-low-disk-space-in-Enterprise-indexer/m-p/610560#M212347</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-23T20:55:09Z</dc:date>
    </item>
  </channel>
</rss>

