- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Huge Lookup File on Search Head by Tripwire Application ( te_assets.csv )
msocops
Loves-to-Learn
12-15-2020
11:28 PM
Hello Splunk Community members,
I am facing an issue with Tripwire, on splunk. It is generating this humongous file ( te_assets.csv ) approximately 26 GB within an hour. Due to this the splunk service stops as in the Search Head there is only a single partition.
Seems like Tripwire keeps updating splunk lookup with a fresh copy of assets data. Is there a way to limit the generated lookup file on Splunk? Or any config changes to be done from Tripwire Side?
Your help/feedback is highly appreciated.
Thanks
