Splunk Enterprise

Kvstore is filling up on search head

jcgever
Explorer

The search head that our security team uses is filling up the /opt/splunk/var/lib/splunk/kvstore/. The directory is about 400+GB. 

To be honest I'm not sure what role the kvstore plays but I'm feeling like it shouldn't be taking up this much space. 

Any tips on how to clean this up without messing with the functionality?

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...