Currently we have an disk space issue in two of the splunk indexer instances and we have separate volume create for storing the indexed data. We found that /opt/splunk/var/run/search peers is consuming nearly 19 GB of disk space and /opt/splunk/var/lib/ is occupying some where around 15 GB most containing the splunk internal data.
Total disk space allotted for 47G 41G 4.1G 91% /opt
1) Is it safe to delete the .bundle files from this location for the indexer instances.
2) What will be the correct solution to prevent the disk crunch issue in future.
kindly guide me on this.
Hi Carsonza, thanks for your inputs, I had found the issue we had a .csv with size of 661MB and along with other knowledge bundles and it was causing the replication issue. When checked the lookup file and found that it was broken, because the fields in the lookup table are data that is not relevant to ServiceNow. On fixing the lookup issue the .csv file size was reduce to 49 MB and it cleared the space issue.