Deployment Architecture

Maximum disk usage quota has been reached - what authorize.conf file to modify

jwalzerpitt
Influencer

I have users getting the "maximum disk usage quota has been reached" message and from other questions and answers I see I need to increase the srchDiskQuota setting in the authorize.conf file.

I have a SHC and when I look for the authorize.conf file I see it in /opt/splunk/etc/system/default/authorize.conf - if I modify the file in that directory and then push out to my SHs, do I need to worry about the /opt/splunk/etc/system/default/authorize.conf  being overwritten when I update Splunk in the future? 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, you do have to worry about the file being overwritten when you update Splunk.  That is why every .conf file says to NOT modify the /default copy.  Always make your changes in a /local directory.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

jwalzerpitt
Influencer

Thx Rich - I'll create a new file under the /local directory

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you do have to worry about the file being overwritten when you update Splunk.  That is why every .conf file says to NOT modify the /default copy.  Always make your changes in a /local directory.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...