Deployment Architecture

Maximum disk usage quota has been reached - what authorize.conf file to modify

jwalzerpitt
Influencer

I have users getting the "maximum disk usage quota has been reached" message and from other questions and answers I see I need to increase the srchDiskQuota setting in the authorize.conf file.

I have a SHC and when I look for the authorize.conf file I see it in /opt/splunk/etc/system/default/authorize.conf - if I modify the file in that directory and then push out to my SHs, do I need to worry about the /opt/splunk/etc/system/default/authorize.conf  being overwritten when I update Splunk in the future? 

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes, you do have to worry about the file being overwritten when you update Splunk.  That is why every .conf file says to NOT modify the /default copy.  Always make your changes in a /local directory.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

jwalzerpitt
Influencer

Thx Rich - I'll create a new file under the /local directory

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, you do have to worry about the file being overwritten when you update Splunk.  That is why every .conf file says to NOT modify the /default copy.  Always make your changes in a /local directory.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...