Monitoring Splunk

The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch

mgaraventa_splu
Splunk Employee
Splunk Employee

On our cluster master server, we saw the following message:

The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch

I've done some research on google and the value is set in server.conf.

Can you please advise what is the impact on changing this to a lower value, e.g. 2000MB?

How can we determine what is the best (lowest) value we can use without any impact on performance?

Should we consider updating this value on search heads, heavy forwarders, indexers?

Thanks.

1 Solution

mgaraventa_splu
Splunk Employee
Splunk Employee

Limits for controlling disk space in Splunk can be changed

The relevant stanza and parameter of interest in server.conf is:

[diskUsage]
minFreeSpace = <num>

For more details please look here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Setlimitsondiskusage

This can be changed on any Splunk installations as explained on the online documentation: "for all installations, including forwarders, you must have a minimum of 5GB of hard disk space available in addition to the space required for any indexes." The default is 5000 and this value can be changed as explained before.

For more details, please check here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Installation/Systemrequirements#Recommended_hardwa...

Hope this helps.

View solution in original post

shockman
Engager

I moved the dispatch dir to a location with more space. I assume this is a sort of search cache.
https://answers.splunk.com/answers/2205/can-i-change-the-path-of-the-dispatch-directory.html#answer-...

mgaraventa_splu
Splunk Employee
Splunk Employee

Limits for controlling disk space in Splunk can be changed

The relevant stanza and parameter of interest in server.conf is:

[diskUsage]
minFreeSpace = <num>

For more details please look here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Setlimitsondiskusage

This can be changed on any Splunk installations as explained on the online documentation: "for all installations, including forwarders, you must have a minimum of 5GB of hard disk space available in addition to the space required for any indexes." The default is 5000 and this value can be changed as explained before.

For more details, please check here:

http://docs.splunk.com/Documentation/Splunk/6.2.1/Installation/Systemrequirements#Recommended_hardwa...

Hope this helps.

Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...