Monitoring Splunk

Minimum Free Disk Space Reached

sidthesloth98
New Member

I've Just set-up a new Single Instance Splunk Server (Version 7.3.2) on a VM with 200GB of space. I've not set up any indexes/searches/apps etc I've literally only run the installer and logged in to the web page.

Why am I getting the following error when I have so much free space on the VM?

"The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch"

Labels (1)
0 Karma
1 Solution

FrankVl
Ultra Champion

Have you checked how that 200GB is configured in the VM's filesystem? Could it be that /opt is on a separate partition or so, and as such not able to make use of the full 200GB?

What does the df -h command tell you?

View solution in original post

0 Karma

FrankVl
Ultra Champion

Have you checked how that 200GB is configured in the VM's filesystem? Could it be that /opt is on a separate partition or so, and as such not able to make use of the full 200GB?

What does the df -h command tell you?

0 Karma

ivanreis
Builder

the space for dispatch files is full. It is possible that splunk is not able to cleanup the files that is being generated, check this article, this will assist you to cleanup the dispatch directory or even adjust the limits.conf for this configuration.
-> https://answers.splunk.com/answers/389879/dispatch-directory-is-full-how-do-we-clear-it-up.html

0 Karma

sidthesloth98
New Member

As was said above, it was a problem with my partitions. I resized the partition and it now works perfectly

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...