Splunk Enterprise Security

Not able to view the prepolulated data on free trial enterprise security sandbox

amakwana
New Member

Search not executed: The minimum free disk space (995MB) reached for /opt/splunk/var/run/splunk/dispatch

0 Karma

PavelP
Motivator

Hello @amakwana

this error means the partition where splunk is installed has only so much (995MB) free space, therefore splunk stopped indexing and searching. You need to allocate more space for splunk.

0 Karma

amakwana
New Member

How would i allocate more space..its free trialcloud sandbox by splunk

0 Karma

PavelP
Motivator

@amakwana

alternatively you can modify this setting in $SPLUNK_HOME/etc/system/local/server.conf

 [diskUsage]
 minFreeSpace = 100

and restart splunk, this will give you some hunderds of MB.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...