Monitoring Splunk

How to fix a disk space warning for /opt/splunk/var/lib/splunk/audit/db

Glasses
Builder
The diskspace remaining=8376 has breached the yellow threshold for filesystems=[/opt/splunk/var/lib/splunk/audit/db]
06-18-2019 14:30:39.377 -0500 WARN DiskMon - MinFreeSpace=5000. The diskspace remaining=8376 is less than 2 x minFreeSpace

In the .../audit dir only db has data, nothing in colddb etc...

I am not sending them to a frozen path, I was hoping they would roll...

How do I set this to roll or drop after it reaches 2GB?

Labels (1)
Tags (3)
0 Karma
1 Solution

martynoconnor
Communicator

If you would rather roll data out by time or space limit, that's something for indexes.conf and you can see how to do that here:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Configureindexstorage

View solution in original post

martynoconnor
Communicator

If you would rather roll data out by time or space limit, that's something for indexes.conf and you can see how to do that here:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Configureindexstorage

Glasses
Builder

thanks, cannot believe I did not think of that...

0 Karma

martynoconnor
Communicator

No worries. 🙂

0 Karma

martynoconnor
Communicator

Hi there,

You can change the value of the free disk space that triggers the warning in limits.conf - see the docs link below:

https://docs.splunk.com/Documentation/Splunk/7.3.0/Indexer/Setlimitsondiskusage#Set_minimum_free_dis...

Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...