Knowledge Management

Overflow /opt/splunk/var/spool/splunk directory

vryzhko
Path Finder

Hello,

We have overflow /opt/splunk/var/spool/splunk directory. It contains stash.new files from 2014 year to today. Splunk doesn't clean their itself.
We used script fill_summary_index.py for clean stash.new files but it didn't take desired result. Files in this directory don't clean.
I don't can find appropriate method for cleaning these files.

Can we to remove manually these files from folder?

Please help!

Tags (1)
0 Karma
1 Solution

evelenke
Contributor
0 Karma

evelenke
Contributor

Try this solution https://answers.splunk.com/answers/294682/the-splunk-homevarspoolsplunk-directory-is-filling.html

In my case this removes all stash_new filews from the folder.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...