Knowledge Management

disk filling with spool dbmon dbmonevt files

bgstein
Path Finder

Among other struggles with DB Connect I'm trying to pull a large amount of historical data into Splunk to see it is possible to migrate a mysql database into Splunk and running into issues with files in dbmon filling the system drive. This is with Splunk (free) running on Windows 2008 R2.

Is it possible to move the dbmon spool via a change to the configuration file? Is there a way to cleanly delete *.dbmonevt files?

Thanks

Tags (1)

araitz
Splunk Employee
Splunk Employee

Many times, this happens because the files have the same checksum for their header and footer. I think you will see events in index=_internal from the fishbucket related to the files in question indicating that they are being skipped because Splunk has already seen them.

0 Karma

ShaneNewman
Motivator

I have never moved the spool to a new location, not to say it is not possible. As far as deleting the events, just shut down splunk, then delete the files from the directory. Make sure you disable the input from dbx that is filling up your drive before restarting splunk.

bgstein
Path Finder

Thanks, that allows me to continue.

It is a shame that you can't manage the size of the spool directory as you can the indexes.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...