Splunk Dev

Splunk's bin/.cache is growing out of proportions. Is there a configuration setting to limit the size?

arkadyz1
Builder

I have a python script which returns all kinds of images via REST interface by going for some external sites to fetch them first. Apparently, the results of all such requests to the external sites are cached in $SPLUNK_HOME/bin/.cache/. Unfortunately, our requests are constantly changing, so, on one hand, we don't really need that cache much, and, on the other hand, that folder is growing because each request is a new one.

At some point, Splunk stops all searches because the root partition has less than 5G free space. That's how we discovered bin/cache - by running around the whole system with du and looking for the offending folder.

Are there any configuration settings allowing us to cap the size of bin/.cache somehow? I couldn't find anything in Splunk Admin manual.

0 Karma
1 Solution

arkadyz1
Builder

OK, it's confirmed: I copy pasted some code from the Internet, getting an http connection like this:

h = httplib2.Http(".cache", timeout = 10)

(timeout was my addition). Once I removed that ".cache" from the parameters, the files stopped appearing there. A strange thing is: the cache was still populating even for requests with 'cache-control' header set to 'no-cache' (a bug in httplib2?)

Consider this more of a "raising the awareness" post.

View solution in original post

0 Karma

arkadyz1
Builder

OK, it's confirmed: I copy pasted some code from the Internet, getting an http connection like this:

h = httplib2.Http(".cache", timeout = 10)

(timeout was my addition). Once I removed that ".cache" from the parameters, the files stopped appearing there. A strange thing is: the cache was still populating even for requests with 'cache-control' header set to 'no-cache' (a bug in httplib2?)

Consider this more of a "raising the awareness" post.

0 Karma

arkadyz1
Builder

I realized that we are using httplib2 and are creating the connection with '.cache' parameter. I'm not completely sure it's the reason, though it may well be...

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...