Deployment Architecture

search head cluster out of space hard disk


I ran out of space in my HSC node. What is the best way to solve this problem? Should I move some of my data to another node, or is there a better way to do this? or can automatically free up space?

The first step is to find out what file/directory is using up the disk space.  Use the du utility for that.  Next, figure out what process is using the disk space.  Is it Splunk, the OS, or another app?  Then you can try to determine the cause.  It could be too many search artifacts filling up the dispatch directory or searches not getting reaped from dispatch, a lookup file may have grown too large, etc.

