Security

postfix and /var/spool/postfix/maildrop directory are having issues on my Splunk server

robertlynch2020
Influencer

HI

My system admins are having issues with the Splunk server on the /var. They are saving it is heavily used. (ONLY in the day time does this look like it is happening!).

For example from 9:30 this morning we have written 600MB in 4 hours. SO they are having to clean it down etc..

We do have alerts, but not at this frequency, any idea what could be going on?

Thanks
Robert Lynch

Tags (1)
0 Karma
1 Solution

robertlynch2020
Influencer

HI

Thanks for your replay, in the end we found the issue.
We have saved a PDF on a dashboard for cron 1 minutes (scheduled PDF delivery ), it was running non stop and caused this issue.

Regards
Robert Lynch

View solution in original post

0 Karma

robertlynch2020
Influencer

HI

Thanks for your replay, in the end we found the issue.
We have saved a PDF on a dashboard for cron 1 minutes (scheduled PDF delivery ), it was running non stop and caused this issue.

Regards
Robert Lynch

0 Karma

gfreitas
Builder

Could you provide more information? It is not clear if you're saying Splunk is causing the issue or postfix. Do you believe Splunk is sending e-mails to your local postfix and that is filling the disk?
You can check with the following search to see if Splunk is sending thousands of e-mails: index=_internal sendemail source="*python.log" and index=_internal sendemail source="*splunkd.log" to have an idea

robertlynch2020
Influencer

HI

Thanks for your replay, in the end we found the issue.
We have saved a PDF on a dashboard for cron 1 minutes (scheduled PDF delivery ), it was running non stop and caused this issue.

Regards
Robert Lynch

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...