Getting Data In

How can I clean up "$splunk_home/var/run/searchpeers" on indexer?

locose
Path Finder

Is there a process to clean up $splunk_home/var/run/searchpeers directory on my indexers? I see *.delta files there from 2 years ago.

kamal_jagga
Contributor

I am also facing same issue ? Indexer is down for few days. A;ready tried dispatch cleanup. Not sure what to do

0 Karma

divyavikas123
Explorer

Hi locose ,
You can delete the older searchpeers,but you first need to stop splunk,and than delete and than start it.As searchpeer contains knowledge objects,and if those knowledge objects are still in use by your search heads(saved searches) than it will be replicated to indexers in the form of search bundles,So if you are having knowledge objects in search heads than u can delete it from search heads.So that next it wont get replicated to indexers.Ask me any query if not get fixed.

Thank you.

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...