Monitoring Splunk

The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch

mgaraventa_splu
Splunk Employee
Splunk Employee

On our cluster master server, we saw the following message:

The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch

I've done some research on google and the value is set in server.conf.

Can you please advise what is the impact on changing this to a lower value, e.g. 2000MB?

How can we determine what is the best (lowest) value we can use without any impact on performance?

Should we consider updating this value on search heads, heavy forwarders, indexers?

Thanks.

1 Solution

mgaraventa_splu
Splunk Employee
Splunk Employee

Limits for controlling disk space in Splunk can be changed

The relevant stanza and parameter of interest in server.conf is:

[diskUsage]
minFreeSpace = <num>

For more details please look here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Setlimitsondiskusage

This can be changed on any Splunk installations as explained on the online documentation: "for all installations, including forwarders, you must have a minimum of 5GB of hard disk space available in addition to the space required for any indexes." The default is 5000 and this value can be changed as explained before.

For more details, please check here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Installation/Systemrequirements#Recommended_hardwa...

Hope this helps.

View solution in original post

shockman
Engager

I moved the dispatch dir to a location with more space. I assume this is a sort of search cache.
https://answers.splunk.com/answers/2205/can-i-change-the-path-of-the-dispatch-directory.html#answer-...

mgaraventa_splu
Splunk Employee
Splunk Employee

Limits for controlling disk space in Splunk can be changed

The relevant stanza and parameter of interest in server.conf is:

[diskUsage]
minFreeSpace = <num>

For more details please look here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Setlimitsondiskusage

This can be changed on any Splunk installations as explained on the online documentation: "for all installations, including forwarders, you must have a minimum of 5GB of hard disk space available in addition to the space required for any indexes." The default is 5000 and this value can be changed as explained before.

For more details, please check here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Installation/Systemrequirements#Recommended_hardwa...

Hope this helps.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...