Deployment Architecture

Changing path or purging data from /opt/splunk/var/run/splunk/dispatch

RVDowning
Contributor

My question is related to this one: http://splunk-base.splunk.com/answers/2205/can-i-change-the-path-of-the-dispatch-directory

I am getting the warning message: The minimum free disk space (2000MB) reached for /opt/splunk/var/run/splunk/dispatch

Namely, I am also running into disk space issues with only 1.5 GB remaining in the partition in which /opt/splunk/var/run/splunk/dispatch resides (60% full). I set the indexing path to /splunk/data with 100 GB available and is only 4% full. Can I change the path of the dispatch directory (using splunk 4.3 on Linux)? Perhaps I don't understand the nature of what is in the dispatch directory. Are these just saved searches? Are these temporary intermediate results? Can this data just be removed? Since the data is still there in the large partition presumably data can always be found again.

Thanks!
Rich

jbsplunk
Splunk Employee
Splunk Employee

You don't have the ability to change where search artifacts are stored, they'll always be in this directory. As noted in the post you reference, you may make this directory into a symbolic link where you have more space available.

These aren't just saved searches, they are ad-hoc searches, and it isn't exactly correct to say they are the searches. What is stored in this folder are the search artifacts, and these artifacts make up the search results. Once the artifacts expire because the TTL for a particular job has been reached, the results will be reaped and the folder for that job will be removed. You may delete anything you'd like in this folder, the only effect you'll see on product functionality is that the results of the searches which you remove the the artifacts for will no longer be available.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...