Splunk stopped index. what is hot_v1_ID

New Member

Splunk stopped indexing when it sent message in splunkd.log

" WARN DatabaseDirectoryManager - Failed getting size of path='/splunk/splunk/var/lib/splunk/audit/db/hotv1592/1470663602-1470663601-4147689500280802279.tsidx.lock':No such file or directory "

What is the problem, and why?

Tags (3)
0 Karma

Re: Splunk stopped index. what is hot_v1_ID


Hi moon92,

those are the hot buckets of your Splunk instance, see the docs for more details

Check for other errors before this message and check maybe your disk space usage. The is a default limit in server.conf of 5000mb, see docs for more details

Beside this, it's hard to provide additional help based on the provided information.

Hope this helps ...

cheers, MuS

0 Karma