I added 4 new search heads to my SHC today. Everything appears to be golden, but the subject directory is filling with 550 MB bundle files. Splunk is not cleaning any of them up. I don't see any log entries related to it.
Splunk Linux x64, 6.6.3.
A rolling restart seems to have addressed it. More SHC gotchas.
View solution in original post
I have 18.8gib in this folder. A rolling restart does not clear it out.
I have the same issue but rolling restart does not resolve the issue . Do you resolve your issue?