Monitoring Splunk

Errors - minimum free disk space - point SPLUNK to new drive

m_martinson
New Member

Basic (free) SPLUNK has been set up on our network, gathering the basic syslog from our firewalls. I'm new here and trying to search through what SPLUNK has been capturing and indexing for security purposes. I am able to login to the web based GUI, but other than having access to a basic summary on the dashboard, I am unable to see any of the logs or conduct any searches due to the following errors:

Search not executed: The minimum free disk space (500MB) reached for C:\Program Files\Splunk\var\run\splunk\dispatch. user=admin

You are low in disk space on partition "C:\Program Files\Splunk\var\lib\splunk\audit\db". Indexing has been paused. Will resume when free disk space rises above 500MB.

In an attempt to resolve the issue(s), I cleared out the existing search results from the "dispatch" folder. That did nothing. I see that there is lots of data in the "audit\db" folder and I know this is the log data, so I do not want to delete that.

Furthermore, I added an additional 100GB drive to the VM currently hosting the SPLUNK server. But barring doing a complete re-install of SPLUNK and pointing all the folders to reside on this new drive, I am uncertain of how to make the existing SPLUNK server/db operate with the newly installed drive.

I'm not even sure the above will solve my problems. So any help would be appreciated.

Tags (2)
0 Karma

ekost
Splunk Employee
Splunk Employee

You'll find some good discussions on Answers about the specific "low on disk space" error such as the topic here. To change which mounted volume an index uses, you can change the homePath and/or coldPath in the indexes.conf file to the new mounted volume. Moving the existing index data to the new mount is covered in an Answers post here.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...