All Apps and Add-ons

/tmp filling up with .crt files

gordo32
Communicator

For every cycle of this add-on it creates a /tmp/httplib2_merged_certificates_xxxxx.crt file where xxxxx is a unique number. The file always contains the same 243 root & intermediate certificates.

After about 1200 times cycling through the add-on stops working. When I clean up these files in /tmp, the add-on continues to work.

Other than a cron job to clean these up periodically does someone have a fix for this.

FYI, using 2.25.10 version of the TA on Splunk Heavy Forwarder 6.6.5.

0 Karma
1 Solution

gordo32
Communicator

It turns out that these .crt files aren't related to this add-on as I first suspected. Uninstalled the add-on and the .crt files continue to collect.

View solution in original post

0 Karma

gordo32
Communicator

It turns out that these .crt files aren't related to this add-on as I first suspected. Uninstalled the add-on and the .crt files continue to collect.

0 Karma

gordo32
Communicator

Also, if it matters at all Ubuntu 16.04 and Splunk is running as Splunk user (not root). Confirmed that the .crt files belong to Splunk user, so not an access issue.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...