Getting Data In

Will deleting the fish bucket file cause forwarder to send all the old data that is already indexed?

spl_unker
Explorer

Hi ,

In one of the OLD UF,  fish bucket has occupied the complete disk space and service has been stopped.  will deleting the fish bucket file cause forwarder to send all the old data that is already indexed ?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

yes, all the log files still present in the system and reachable by the inputs.conf stanzas will be indexed again.

Probably the only way is to give more space to the Splunk partition.

Ciao.

Giuseppe

View solution in original post

spl_unker
Explorer

Thanks for the confirmation @gcusello 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

yes, all the log files still present in the system and reachable by the inputs.conf stanzas will be indexed again.

Probably the only way is to give more space to the Splunk partition.

Ciao.

Giuseppe

impurush
Contributor

Hi @gcusello,

Is there any mechanism to clear the entries from the fish bucket after some time or let's say if I set the limit in the fish bucket,  which part of the fish bucket gets reduced to like 1 GB fish bucket, and if I set 500 MB and what would be deleted?

Increasing the space for the fish bucket is not the solution I am looking for because it may not have the entries from the old as the retention period in the server is less but the number of rotated files is more.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @impurush,

you can find how to clean the fishbucket in this answer https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-data-from-a-forwarder/m-p/93310

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...