Knowledge Management

If my coldToFrozenDir is full or unavailable, do I lose my old data?

faol
Explorer

From can I see, Splunk continues to run but I would like to know what happens to the cold data which meets the criteria to be frozen? Once the frozen directory is made accessible, does Splunk continue to freeze the data, or was it already removed from the index?

0 Karma

bpaul_splunk
Splunk Employee
Splunk Employee

What occurs is the following.

  1. The script to move data to the frozen directory is run.
  2. There is no space to copy the data, or access is not available. This is logged in splunkd.log under the BucketMover category. The message will look something like the following. ERROR BucketMover - aborting move because recursive copy from src='/opt/splunk/var/lib/splunk/_internaldb/db/db_1435901691_1435696540_1132' to dst='/tmp/test/inflight-db_1435901691_1435696540_1132' failed (reason='Permission denied')
  3. The cold bucket is not removed.
  4. Once the issue preventing the script from freezing your data is resolved, the normal freezing process will resume.

If no action is taken to resolve the issue, the disk will eventually fill up and all indexing will stop.

Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...