Monitoring Splunk

Why won't disk space Health Status alert go away?

jankowsr
Path Finder

Splunk Enterprise 8.0.4.1

There was a low disk space issue and Health Status alert was raised as expected. But now there is plenty of disk space and the message says:

04-22-2022 15:05:05.257 +0000 WARN DiskMon - MinFreeSpace=5000. The diskspace remaining=221121 is less than 2 x minFreeSpace

jankowsr_0-1650640098860.png

221121 is definitely not less than than 2x5000

Am I missing something or is it a bug?

Labels (1)
0 Karma

jankowsr
Path Finder
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@jankowsr  - Can you please once try to run Health Checks manually once? (Settings > Monitoring Console > Health Check > Start)

* Also, open Splunk in Incognito Window to see the results once.

-------
I hope this helps!!

0 Karma

jankowsr
Path Finder

the disk_space check passes but it does not seem to clear alert

jankowsr_0-1650648248783.png

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@jankowsr  - I would check on my browser incognito windows.

And wait for a day to see if it gets auto resolved if it's not mission critical.

Otherwise/Then I will raise a support case with Splunk.

0 Karma

jankowsr
Path Finder

The screenshot I provided was already incognito window.

And in my opinion the fact whether it was incognito mode or not should not matter. At the end web application should manage cookies/etags/browser cache/whatever and if it needs incognito window in order to work properly I would still consider it as a bug. Unless we suspect that client browser or intermediate proxy does not honor web standards but it's typically not the case.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...