Getting Data In

Problem as per screen shot - 500MB min disk space reached

Tonyrakus
Explorer

Hi Guys

I have Splunk enterprise installed. I have pulled across some directory's with files inside ( from Kali ).

The issue is I cannot bring up the files in the search and reporting app..

I believe it is because of the Messages in the screen shot below.. which I have no idea how to fix.. even after reading some forums..

I am non IT person.. and new to Splunk.

Any help would be great .

Tonyrakus_0-1597970896138.pngTonyrakus_0-1597970896138.png

 

0 Karma

Tonyrakus
Explorer

This is another screen shot of the index path the data writes to.. I need to somehow get more space..

 

Tonyrakus_0-1597976706059.pngTonyrakus_0-1597976706059.png

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as you already noticed, you are running out of disc space. You must get additional volume for splunk indexes. Then you have two options: increase /opt/splunk or create own fs/volume group + splunk volume where you move your indexes. There are many examples how this should do on answers. 
r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...