Getting Data In

tsidx topologycruncy

baoctac
New Member

Sifting through the discussions about tsidx files, I still find myself confused on how these populate. Currently on my search head, there are 25GB in the tsidx/topologyCrunch directory. The only apps I have installed are Splunk App for AWS and Nessus. From the Settings > Report Acceleration Summary, no accelerations are configured.

My questions are: 1) how can i determine where these files are coming from, and 2) how do i go about removing them.

Thanks!

Tags (1)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

These are coming from a tscollect command in one of your saved searches.

The saved search is probably called "topologyCronSearch".

To remove them, delete the saved search and restart OR disable the saved search and manually delete them from the file system. You should make sure you're not using anything related to the search first though. Most likely, Somewhere there is another search that's looking at these files. Removing the files will cause tstats commands that rely on them to begin failing.

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

These are coming from a tscollect command in one of your saved searches.

The saved search is probably called "topologyCronSearch".

To remove them, delete the saved search and restart OR disable the saved search and manually delete them from the file system. You should make sure you're not using anything related to the search first though. Most likely, Somewhere there is another search that's looking at these files. Removing the files will cause tstats commands that rely on them to begin failing.

0 Karma

baoctac
New Member

Awesome! Thanks jkat54. I found a reference under a saved search with the reference to 'namespace=topologyCronSearch'. looks like this search (called Config: Topology Data Generator) was set up alongside the Splunk App for AWS App.

0 Karma

piebob
Splunk Employee
Splunk Employee

if this answered your question, please 'accept' it 🙂

0 Karma

baoctac
New Member

Done. Thanks!

0 Karma

jkat54
SplunkTrust
SplunkTrust

Can you give the full path to the folder in question please?

0 Karma

baoctac
New Member

Hi,
The full path is /opt/splunk/var/lib/splunk/tsidxstats/topologyCronSearch

Thanks.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...