Monitoring Splunk

How to fix a disk space warning for /opt/splunk/var/lib/splunk/audit/db

Glasses
Builder
The diskspace remaining=8376 has breached the yellow threshold for filesystems=[/opt/splunk/var/lib/splunk/audit/db]
06-18-2019 14:30:39.377 -0500 WARN DiskMon - MinFreeSpace=5000. The diskspace remaining=8376 is less than 2 x minFreeSpace

In the .../audit dir only db has data, nothing in colddb etc...

I am not sending them to a frozen path, I was hoping they would roll...

How do I set this to roll or drop after it reaches 2GB?

Labels (1)
Tags (3)
0 Karma
1 Solution

martynoconnor
Communicator

If you would rather roll data out by time or space limit, that's something for indexes.conf and you can see how to do that here:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Configureindexstorage

View solution in original post

martynoconnor
Communicator

If you would rather roll data out by time or space limit, that's something for indexes.conf and you can see how to do that here:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Configureindexstorage

Glasses
Builder

thanks, cannot believe I did not think of that...

0 Karma

martynoconnor
Communicator

No worries. 🙂

0 Karma

martynoconnor
Communicator

Hi there,

You can change the value of the free disk space that triggers the warning in limits.conf - see the docs link below:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...