We've got a lot of these files (100+) kicking about in our indexes, just wondering if anyone knows what they are (I'm guessing they're a kind of lock file), but I would like to understand why they're being created and the splunkd logic when it encounters a bucket with one of these files.
Anyone encountered these before?
I believe the answer to your question is covered here:
http://splunk-base.splunk.com/answers/2143/what-are-the-sentinel-files-in-splunk_db-for
I believe the answer to your question is covered here:
http://splunk-base.splunk.com/answers/2143/what-are-the-sentinel-files-in-splunk_db-for
Yep, I had seen that, but I was really wondering if they'd been renamed for were a different variant or for a different purpose.