Splunk Enterprise

Ramifications of deleting Splunk Search Artifacts in Dispatch


Good Afternoon Everyone,


I am an ISSO who just inherited a Splunk environment. I have been leaning heavily on this community and i have received lots of great feed back in regards to different documents.  My latest problem is that my dispatch directory is nearing capacity and only has 3 out of 5 GB left so therefore i can't conduct any new searches or get dashboards everything is at a standstill.


I am aware i can use a command to clear artifacts from the dispatch directory and I am aware there are ways to allocate more space or re-direct the dispatch directory...but what I am truly worried about is am I going to lose information by clearing the dispatch directory of artifacts? 


I am concerned about losing security related data or auditable events. is there any one who can break down what exactly a search artifact in Splunk contains? and is it something I need to have on hand for security purposes down the road? I feel if i can show my colleagues what a search artifact is and perhaps why we dont need to worry about deleting it (OR WORRY ) than i can proceed forward... I don't exactly have my organization telling me I need to keep the artifacts but that doesn't mean i shouldn't err on the side of caution.  ANY HELP is greatly appreciated. 

More Info:


All we care about is auditing the devices connected to Splunk by way of queries and dashboards. as long as that data is not compromised we are good.

Labels (2)
0 Karma


The dispatch directory contains information about outstanding searches as well the results from completed searches.  Completed searches should be cleaned up automatically after 10 minutes (default setting), but can be as long as 7 days if the results are shared by the user who ran the search.

Deleting files from the dispatch directory has no affect on your data - that's always safe in your indexes.  A deleted artifact could cause a dashboard to fail, however, if it tries to use the results of a saved search that are no longer there.

If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...