All Apps and Add-ons

estreamer 4.09 causing large knowledge bundles

rsanders30
Path Finder

Happy New Year to all. I am trying to resolve some of the issues I'm coming across with estreamer/encore add-on 4.09. After installing, I've noticed some issues. The main one is the app is causing the knowledge bundle ($SPLUNK\var\run\*.bundle) to fill up (19GB). My current config is set to the default ~2GB. Eventually, the estreamer will stop and I'll stop receiving updates. This didn't happen in the previous versions. I did try to blacklist the data folder in the encore add-on app to not allow it to be bundled, but no luck. 

Anyone having similar issues? 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...