Getting Data In

How can I clean up "$splunk_home/var/run/searchpeers" on indexer?

locose
Path Finder

Is there a process to clean up $splunk_home/var/run/searchpeers directory on my indexers? I see *.delta files there from 2 years ago.

kamal_jagga
Contributor

I am also facing same issue ? Indexer is down for few days. A;ready tried dispatch cleanup. Not sure what to do

0 Karma

divyavikas123
Explorer

Hi locose ,
You can delete the older searchpeers,but you first need to stop splunk,and than delete and than start it.As searchpeer contains knowledge objects,and if those knowledge objects are still in use by your search heads(saved searches) than it will be replicated to indexers in the form of search bundles,So if you are having knowledge objects in search heads than u can delete it from search heads.So that next it wont get replicated to indexers.Ask me any query if not get fixed.

Thank you.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...