Splunk Enterprise

Knowledge bundle Error : directory contains large lookup file

Master_Blaster
Explorer

Hi All, 
I have an Warning message on my search head GUI as below:

"The current bundle directory contains a large lookup file that might cause bundle replication fail. The path to the directory is /opt/splunk/var/run/hostename-randomnumber-randomnumber.delta"

When i validated respective delta file, it's not even one MB. Still getting this Warning message frequently. Could anyone please help ? i see same messages on splunkd.log too.


-rw------- 1 root root 188M Apr 2 10:36 hostname-1617352591.bundle
-rw------- 1 root root 80K Apr 2 10:36 hostname-1617352525-1617352591.delta

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

That warning is triggered by a lookup file that is larger than 50MB.  If this is not a concern for you then consider changing the value of  conf_replication_summary.concerning_file_size in server.conf.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That warning is triggered by a lookup file that is larger than 50MB.  If this is not a concern for you then consider changing the value of  conf_replication_summary.concerning_file_size in server.conf.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rajuljain
Observer

How to get the lookup file name causing issue?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Examine the bundle file.  tar -tf <bundle-file-name>

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...