Splunk Enterprise Security

$SPLUNK_HOME/var/lib/splunk/modinputs taking up disk space


Hi All,

The data checkpoint file for cloudtrail logs is taking up a lot of disk space (over 100 GB). Is this a normal behaviour?
Where can I check the modular input script. We are having issues of full disk space due to this.
Any help would be appreciated

0 Karma



I have got similar issue. Were you able to solve it?

0 Karma


Hi @navarec  -

I’m a Community Moderator in the Splunk Community. 
This question was posted 4 years ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the  visibility it deserves. To increase your chances of getting help from the community, follow these guidelines in the Splunk Answers User Manual when creating your post.

Thank you! 

Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...