Splunk Enterprise

Wrong volume usage reported on monitoring console and "_introspection" index

ktn01
Path Finder

Hello

I have a volume with a filesystem mountpoint as VolumePath.

The page "volume Detail: Instance" on monitoring console say me that the "volume usage" on this volume is ~26'400GB but the "df" command on operating system say me that the usage is ~21'416GB

I have enabled "tsidxreduction" recently.

Any Idee why do I have a about 5TB more by Splunk usage as by Filesystem usage?

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...