Knowledge Management

Overflow /opt/splunk/var/spool/splunk directory

vryzhko
Path Finder

Hello,

We have overflow /opt/splunk/var/spool/splunk directory. It contains stash.new files from 2014 year to today. Splunk doesn't clean their itself.
We used script fill_summary_index.py for clean stash.new files but it didn't take desired result. Files in this directory don't clean.
I don't can find appropriate method for cleaning these files.

Can we to remove manually these files from folder?

Please help!

Tags (1)
0 Karma
1 Solution

evelenke
Contributor
0 Karma

evelenke
Contributor

Try this solution https://answers.splunk.com/answers/294682/the-splunk-homevarspoolsplunk-directory-is-filling.html

In my case this removes all stash_new filews from the folder.

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...