Getting Data In

file descriptor cache is full - trimming...

a212830
Champion

Hi,

I'm getting a lot of "File descriptor cache is full (100), trimming..." messages on a couple of my windows servers that are running UF. Can someone tell me what this means?

rgcurry
Contributor

I have gotten this too when the Forwarder has been setup on a server with a lot of files in the monitored directory. This message indicates that there are more files than the Forwarder can handle at one time. It is not a problem, notice that the message level is set to "INFO". Within time, and this depends upon how many files you have and the number of open files handles are defined for the Forwarder, it will catch up and process all of your logs.

You can get more specific info with the Answer to the question "4.1.2 upgrade TailingProcessor - File descriptor cache is full"

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...