I have this problem:
The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch.
So I cannot delete my data because splunk is full, I have tried to digit from command line :
./splunk clean eventdata -f
and I have tried to erase all my log from the splunk folder, but I have still the same problem.
Please can someone help me?
in my case, was the solution etit policy. just like the documentation (http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Setlimitsondiskusage) and also http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Setaretirementandarchivingpolicy
-->Set a retirement and archiving policy
You made the value larger? So now it is expecting 20GB free? What is your free disk space left on your host? Is this running on a laptop or something with very little disk space left?