Hello Splunk community,
I have an issue with a Splunk Deployment Server where FS /var is of size 30Gb and currently 22G are being used by the log "uncategorised.log" under the path /var/log/syslog. Is it viable/possible to delete that log or make a backup of it to a tape or a different server.?
Talk to your Linux admin about that. Splunk does not write to /var so that is not a Splunk file.
Talk to your Linux admin about that. Splunk does not write to /var so that is not a Splunk file.