All Apps and Add-ons

tsidxstats is filling up for the Search Activity app

SCGvdPal
New Member

We've installed the "Search activity" on our Monitoring Console. However, due to a couple of tscollect commands the tsidxstats directory is filling up rapidly, causing the monitoring console to crash. We now remove the files using a cronjob, but is there a cleaner way to resolve this issue?
We use the 2.2.12 version of this app, but an upgrade to 3.0.1 had a few other unexpected and unwanted consequences and we therefore reverted back to the 2.2.12 version.
The directory that is filling up is /opt/splunk/var/lib/splunk/tsidxstats.

0 Karma

codebuilder
SplunkTrust
SplunkTrust

Move your SPLUNK_DB to another disk (SAN or virtual) and away from the OS disk.

You can change this within /opt/splunk/etc/splunk-launch.conf.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...