Deployment Architecture

How do I see what/if buckets were deleted by Splunk and why?

pinVie
Path Finder

Hi all,

We currently have the situation where some buckets are disappearing from Splunk. So my question is, how do I see what/if buckets were deleted by Splunk (e.g., because of insufficient storage) and maybe a reason for the buckets being deleted?

Personally I think that something on the SAN in the background is weird, but I'd like to check Splunk.

Thank you

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

The only time Splunk deletes buckets is when cold data is frozen and you don't have an archive script in place. Deleted buckets are logged to SPLUNK_HOME/var/log/splunk/splunkd_stdout.log.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

The only time Splunk deletes buckets is when cold data is frozen and you don't have an archive script in place. Deleted buckets are logged to SPLUNK_HOME/var/log/splunk/splunkd_stdout.log.

---
If this reply helps you, Karma would be appreciated.

pinVie
Path Finder

Hi - so our issue was that we created a volume like this:

[volume:index]
path = $SPLUNK_DB
maxVolumeDataSizeMB = 15000000

but maxTotalDataSizeInMB remaind 500000.
What we did now is to increase maxTotalDataSizeInMB to 4294967295 for all relevant indexes.

Thank you !

cboillot
Contributor

Has this changed in the new versions? Where can I find this in v7.x?

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...