The search head that our security team uses is filling up the /opt/splunk/var/lib/splunk/kvstore/. The directory is about 400+GB.
To be honest I'm not sure what role the kvstore plays but I'm feeling like it shouldn't be taking up this much space.
Any tips on how to clean this up without messing with the functionality?