Getting Data In

build up of files left behind in $SPLUNK_HOME/var/spool/splunk

jarjoh42
Path Finder

I am getting the same buildup of files in the $SPLUNK_HOME/var/spool/splunk. These are STACH_NEW files. I understand this is because of bug SPL-59578 as referenced in this post : http://splunk-base.splunk.com/answers/64018/files-left-in-splunk_homevarspoolsplunk

I have also referenced this posting: http://splunk-base.splunk.com/answers/70072/summary-indexing-blocked-and-binary-file-warning
and attempted the fixes in both with no success.

My question is there a work around for this problem an is it safe to continue to remove these files from the folder.

Also if I could just move the files to different drive it would be fine.
The current stanzas I have written for these inputs are

Splunk\etc\system\local.inputs.conf

[monitor://$SPLUNK_HOME\var\spool\splunk\...stash_new]
move_policy = sinkhole
disabled = 0

Splunk\etc\system\local.props.conf

[stash_new] NO_BINARY_CHECK=1
Tags (2)
0 Karma

yannK
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...