Deployment Architecture

Can I safely remove old cluster remote-bundle directories to free up disk space?

Explorer

I am using up a lot of disk space under ${SPLUNK_HOME}/var/run/splunk/cluster/remote-bundle on our Cluster Manager/Master and noticed that it seems like all of the Remote Bundles ever created are still taking up space in this directory.

I would like to know if I can safely remove the older directories or if there is a command I should use for doing this. Also, is there a setting for telling Splunk to only keep a certain number of previous bundles?

Explorer

I ended up opening a ticket with Splunk and they let me know that this is a known issue and is scheduled to be fixed in a future release. Until then, they suggest that you be very careful removing any of these and make sure you do not remove the current one in use and keep something like 5 to 10 older ones. Otherwise, it is safe to remove the old ones.

Communicator

I am also facing the same issue in Splunk 6.2.3. Which version are you running?

0 Karma

Explorer

I am running 6.2.4

0 Karma

Path Finder

We are now running into this issue and we are using 6.3.3.

0 Karma

Still present in 6.4 !

0 Karma

Path Finder

Large bundles is not a Splunk issue but usaully an issue with large lookups which should not be pushed to the indexers.
Try to blacklist lookups so they won't get pushed to the indexers.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!