Getting Data In

file descriptor cache is full - trimming...

a212830
Champion

Hi,

I'm getting a lot of "File descriptor cache is full (100), trimming..." messages on a couple of my windows servers that are running UF. Can someone tell me what this means?

rgcurry
Contributor

I have gotten this too when the Forwarder has been setup on a server with a lot of files in the monitored directory. This message indicates that there are more files than the Forwarder can handle at one time. It is not a problem, notice that the message level is set to "INFO". Within time, and this depends upon how many files you have and the number of open files handles are defined for the Forwarder, it will catch up and process all of your logs.

You can get more specific info with the Answer to the question "4.1.2 upgrade TailingProcessor - File descriptor cache is full"

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...