Knowledge Management

Overflow /opt/splunk/var/spool/splunk directory

vryzhko
Path Finder

Hello,

We have overflow /opt/splunk/var/spool/splunk directory. It contains stash.new files from 2014 year to today. Splunk doesn't clean their itself.
We used script fill_summary_index.py for clean stash.new files but it didn't take desired result. Files in this directory don't clean.
I don't can find appropriate method for cleaning these files.

Can we to remove manually these files from folder?

Please help!

Tags (1)
0 Karma
1 Solution

evelenke
Contributor
0 Karma

evelenke
Contributor

Try this solution https://answers.splunk.com/answers/294682/the-splunk-homevarspoolsplunk-directory-is-filling.html

In my case this removes all stash_new filews from the folder.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...