Knowledge Management

If my coldToFrozenDir is full or unavailable, do I lose my old data?

faol
Explorer

From can I see, Splunk continues to run but I would like to know what happens to the cold data which meets the criteria to be frozen? Once the frozen directory is made accessible, does Splunk continue to freeze the data, or was it already removed from the index?

0 Karma

bpaul_splunk
Splunk Employee
Splunk Employee

What occurs is the following.

  1. The script to move data to the frozen directory is run.
  2. There is no space to copy the data, or access is not available. This is logged in splunkd.log under the BucketMover category. The message will look something like the following. ERROR BucketMover - aborting move because recursive copy from src='/opt/splunk/var/lib/splunk/_internaldb/db/db_1435901691_1435696540_1132' to dst='/tmp/test/inflight-db_1435901691_1435696540_1132' failed (reason='Permission denied')
  3. The cold bucket is not removed.
  4. Once the issue preventing the script from freezing your data is resolved, the normal freezing process will resume.

If no action is taken to resolve the issue, the disk will eventually fill up and all indexing will stop.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...