Monitoring Splunk

The index processor has paused data flow

rgarcia
Engager

After a hardware failure was resolved, I attempted to start splunk again...but I am now getting this error

"The index processor has paused data flow. Current free disk space on partition '/' has fallen to 158MB, below the minimum of 5000MB. Data writes to index path '/data1/splunk/indexes/audit/db'cannot safely proceed. Increase free disk space on partition '/' by removing or relocating data."

I understand what is saying, but the odd part is that partition "/" never had that much space and all other indexers are configured the same with no issues.

What am I missing here?

Labels (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Can it be so that your node hasn’t mount all FSs yet?

You should check what is your SPLUNK_DB path and then check that it’s present and it has enough space.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can it be so that your node hasn’t mount all FSs yet?

You should check what is your SPLUNK_DB path and then check that it’s present and it has enough space.

r. Ismo

0 Karma

rgarcia
Engager

You're right, mount points were missing. thank you

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...