Getting Data In

Can we delete Disk_objects.log file in Splunk Universal Forwarder ?

Venkat_16
Contributor

We have only 2 GB of minimum disk space allocated for Splunk universal forwarder and my envirnoment team has asked to reduce the size consumed. I cleared splunk internal logs and also changes limit.conf but i found disk._objects file consuming more space. Is it safe to delete the file. the splunk version we are using is 7.0.0

0 Karma
1 Solution

p_gurav
Champion

Can you check,:

The introspection generator add-on iin the forwarder's $SPLUNK_HOME/etc/apps/introspection_generator_addon/local/app.conf,

[install]
state = enabled

You can disable it if you don't want this data.

Refer doc:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/Whatdatagetslogged

View solution in original post

0 Karma

p_gurav
Champion

Can you check,:

The introspection generator add-on iin the forwarder's $SPLUNK_HOME/etc/apps/introspection_generator_addon/local/app.conf,

[install]
state = enabled

You can disable it if you don't want this data.

Refer doc:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/Whatdatagetslogged

0 Karma

Venkat_16
Contributor

But does it cause any harm to the forwarder like if we clear fish bucket data, the forwarder will re-index the past stuff, similarly if we remove those files, does it cause any issue.

thanks for your support

0 Karma

p_gurav
Champion

According to doc it is disabled by default. In your environment those log may enabled for troubleshooting purpose. But yes you can disable it.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...