Getting Data In

Is it expected behavior for Hunk to delete files as they age from the dispatch directory used for MapReduce?

splunkIT
Splunk Employee
Splunk Employee

We are using Hunk with MapR. There is a dispatch directory that Hunk uses for the reduce of the map reduce. /mapr/tmp/dispatch.

We are seeing files deleted from this directory while the search is progressing: First the heartbeat file, and then the sub directories.
The search has not completed and this hangs the search job forever.

Is this part of Hunk to delete these files as they age? If so, what is the delete age and or setting to control it?

We are also seeing any non hunk file being deleted from this directory. Is Hunk deleting them?

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

Overall – yes this is expected. Hunk deletes the files under the Hunk HDFS working directory.
What is not expected, is that it will delete these files before the job is completed and these files are still needed

0 Karma

ddrillic
Ultra Champion

How does the directory structure look under /mapr/tmp/dispatch? Each search job should have its own directory...

0 Karma

rdagan_splunk
Splunk Employee
Splunk Employee

Do you have two instances of Hunk pointing to the same Hunk working directory in HDFS?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...