Getting Data In

limits.conf is not present under /opt/splunk/etc/system/local

prateeksawhney
Explorer

Hi All,

I need your help urgently, I am facing issue with one of the forwarder as it keeps taking lots of space in /opt directory and due to which sometimes it stops running. Upon checking further I noticed that this directory is taking maximum space.

/opt/splunk/var/lib/splunk/fishbucket/splunk_private_db
 
On further investigation I came to know that if I do changes in limits.conf file I can limit size of this directory.
But unfortunately I cannot find this file limits.conf under /opt/splunk/etc/system/local. 
 
Please suggest what can I do about it. Any replies to this will be highly appreciated. Also please correct me if I am using a wrong approach here.
 
Thanks in advance.
Prateek
Labels (1)
0 Karma

manjunathmeti
Champion

Hi @prateeksawhney,

You need to create new limits.conf file in  /opt/splunk/etc/system/local/. 
FYI: Default config files exist in /opt/splunk/etc/system/default/ but you should never edit these.

If this reply helps you, an upvote/like would be appreciated.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...