Splunk Enterprise

Kvstore is filling up on search head

jcgever
Explorer

The search head that our security team uses is filling up the /opt/splunk/var/lib/splunk/kvstore/. The directory is about 400+GB. 

To be honest I'm not sure what role the kvstore plays but I'm feeling like it shouldn't be taking up this much space. 

Any tips on how to clean this up without messing with the functionality?

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...