Deployment Architecture

Can I safely remove old cluster remote-bundle directories to free up disk space?

datajock
Explorer

I am using up a lot of disk space under ${SPLUNK_HOME}/var/run/splunk/cluster/remote-bundle on our Cluster Manager/Master and noticed that it seems like all of the Remote Bundles ever created are still taking up space in this directory.

I would like to know if I can safely remove the older directories or if there is a command I should use for doing this. Also, is there a setting for telling Splunk to only keep a certain number of previous bundles?

datajock
Explorer

I ended up opening a ticket with Splunk and they let me know that this is a known issue and is scheduled to be fixed in a future release. Until then, they suggest that you be very careful removing any of these and make sure you do not remove the current one in use and keep something like 5 to 10 older ones. Otherwise, it is safe to remove the old ones.

vsingla1
Communicator

I am also facing the same issue in Splunk 6.2.3. Which version are you running?

0 Karma

datajock
Explorer

I am running 6.2.4

0 Karma

robert_miller
Path Finder

We are now running into this issue and we are using 6.3.3.

0 Karma

USPSSplunkSuppo
Explorer

Still present in 6.4 !

0 Karma

cmeerbeek
Path Finder

Large bundles is not a Splunk issue but usaully an issue with large lookups which should not be pushed to the indexers.
Try to blacklist lookups so they won't get pushed to the indexers.

Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...