Deployment Architecture

Splunk is using the wrong disk for some reason - why ?

sbenamro
New Member

I have 2 drives - C and D on the indexer.
I've defined the D drive for the indexing.
yet Splunk Folder is using 19GB - I've noticed that the biggest folder is C:\Program Files\Splunk\var\run\searchpeers
which uses 13GB.

what am I missing here ?

oh and this indexer is the licenser as well.

Tags (1)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

$SPLUNK_HOME/var/run/searchpeers stores bundles from your search heads used by the indexer to run searches for them with the appropriate configurations. Indexing happens elsewhere, by default in $SPLUNK_HOME/var/lib/splunk - see if that's fairly small compared to what you've defined on your second drive to confirm that the index path setting is working.

As for your searchpeers folder using 13GB, this can have several reasons:
- is your bundle huge, e.g. massive lookup files?
- do you have many search heads, each distributing different bundles? Consider merging the search heads into a search head cluster, reducing the number of different bundles on your indexers.
- are there old bundles from legacy search heads? These can be deleted.

0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...