Deployment Architecture

Splunk stopped index. what is hot_v1_ID

moon92
New Member

Splunk stopped indexing when it sent message in splunkd.log

" WARN DatabaseDirectoryManager - Failed getting size of path='/splunk/splunk/var/lib/splunk/audit/db/hot_v1_592/1470663602-1470663601-4147689500280802279.tsidx.lock':No such file or directory "

What is the problem, and why?

Tags (3)
0 Karma

MuS
Legend

Hi moon92,

those are the hot buckets of your Splunk instance, see the docs for more details http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/HowSplunkstoresindexes#Bucket_names

Check for other errors before this message and check maybe your disk space usage. The is a default limit in server.conf of 5000mb, see docs for more details http://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Serverconf#Disk_usage_settings_.28for_the_in...

Beside this, it's hard to provide additional help based on the provided information.

Hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...