Getting Data In

Problem as per screen shot - 500MB min disk space reached

Tonyrakus
Explorer

Hi Guys

I have Splunk enterprise installed. I have pulled across some directory's with files inside ( from Kali ).

The issue is I cannot bring up the files in the search and reporting app..

I believe it is because of the Messages in the screen shot below.. which I have no idea how to fix.. even after reading some forums..

I am non IT person.. and new to Splunk.

Any help would be great .

Tonyrakus_0-1597970896138.png

 

0 Karma

Tonyrakus
Explorer

This is another screen shot of the index path the data writes to.. I need to somehow get more space..

 

Tonyrakus_0-1597976706059.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as you already noticed, you are running out of disc space. You must get additional volume for splunk indexes. Then you have two options: increase /opt/splunk or create own fs/volume group + splunk volume where you move your indexes. There are many examples how this should do on answers. 
r. Ismo

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...