Getting Data In

Can we delete Disk_objects.log file in Splunk Universal Forwarder ?

Venkat_16
Contributor

We have only 2 GB of minimum disk space allocated for Splunk universal forwarder and my envirnoment team has asked to reduce the size consumed. I cleared splunk internal logs and also changes limit.conf but i found disk._objects file consuming more space. Is it safe to delete the file. the splunk version we are using is 7.0.0

0 Karma
1 Solution

p_gurav
Champion

Can you check,:

The introspection generator add-on iin the forwarder's $SPLUNK_HOME/etc/apps/introspection_generator_addon/local/app.conf,

[install]
state = enabled

You can disable it if you don't want this data.

Refer doc:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/Whatdatagetslogged

View solution in original post

0 Karma

p_gurav
Champion

Can you check,:

The introspection generator add-on iin the forwarder's $SPLUNK_HOME/etc/apps/introspection_generator_addon/local/app.conf,

[install]
state = enabled

You can disable it if you don't want this data.

Refer doc:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/Whatdatagetslogged

0 Karma

Venkat_16
Contributor

But does it cause any harm to the forwarder like if we clear fish bucket data, the forwarder will re-index the past stuff, similarly if we remove those files, does it cause any issue.

thanks for your support

0 Karma

p_gurav
Champion

According to doc it is disabled by default. In your environment those log may enabled for troubleshooting purpose. But yes you can disable it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...