Getting Data In

Universal Forwarder Fishbucket growing.

NHLaurent
Explorer

Hi All,

The UF (6.6.2) on our AIX server has an issue where the fishbuckets are growing in size 3gb + even after setting the file_tracking_db_threshold_mb = 500.
Is there a way to invoke a retirement policy?
If we reduce the value to 200, I understand this will in turn create smaller multiple buckets not necessarily solve the issue but will those buckets age out sooner.

Thanks

1 Solution

NHLaurent
Explorer

Well It seems to have been a bug with AIX and UF version 6.6.2. We upgrade one to 7.1.2 and seems to have resolved the issue.

View solution in original post

0 Karma

NHLaurent
Explorer

Well It seems to have been a bug with AIX and UF version 6.6.2. We upgrade one to 7.1.2 and seems to have resolved the issue.

0 Karma

ddrillic
Ultra Champion

@yannK spoke about it at Why is fishbucket getting really big on my Universal Forwarder?

He said -

-- It's like thermodynamics, the fishbucket/btree is the entropy of your file system. It can only grow with the time.

So, it's interesting to see the complexity of your monitoring set-up.

-- Remark : as we maintain a backup copy, the disk space used is actually 2 times the limit, and sometimes 3 times the limit when a temporary file if generated for the new backup.

But this remark doesn't explain your 3gb + of usage.

0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...