All Apps and Add-ons

estreamer 4.09 causing large knowledge bundles

Path Finder

Happy New Year to all. I am trying to resolve some of the issues I'm coming across with estreamer/encore add-on 4.09. After installing, I've noticed some issues. The main one is the app is causing the knowledge bundle ($SPLUNK\var\run\*.bundle) to fill up (19GB). My current config is set to the default ~2GB. Eventually, the estreamer will stop and I'll stop receiving updates. This didn't happen in the previous versions. I did try to blacklist the data folder in the encore add-on app to not allow it to be bundled, but no luck. 

Anyone having similar issues? 

Labels (3)
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!