Getting Data In

Will deleting the fish bucket file cause forwarder to send all the old data that is already indexed?

spl_unker
Explorer

Hi ,

In one of the OLD UF,  fish bucket has occupied the complete disk space and service has been stopped.  will deleting the fish bucket file cause forwarder to send all the old data that is already indexed ?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

yes, all the log files still present in the system and reachable by the inputs.conf stanzas will be indexed again.

Probably the only way is to give more space to the Splunk partition.

Ciao.

Giuseppe

View solution in original post

spl_unker
Explorer

Thanks for the confirmation @gcusello 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

yes, all the log files still present in the system and reachable by the inputs.conf stanzas will be indexed again.

Probably the only way is to give more space to the Splunk partition.

Ciao.

Giuseppe

impurush
Contributor

Hi @gcusello,

Is there any mechanism to clear the entries from the fish bucket after some time or let's say if I set the limit in the fish bucket,  which part of the fish bucket gets reduced to like 1 GB fish bucket, and if I set 500 MB and what would be deleted?

Increasing the space for the fish bucket is not the solution I am looking for because it may not have the entries from the old as the retention period in the server is less but the number of rotated files is more.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @impurush,

you can find how to clean the fishbucket in this answer https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-data-from-a-forwarder/m-p/93310

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...