Splunk Enterprise

indexer reached disk space

sarit_s
Communicator

Hello,

In one of out indexer we reached disk space in /var

this is the path that takes all the space:
opt/splunk/var/lib/splunk/prod/datamodel_summary

 

can i delete the files there ?

how can i avoid this messages ?

if it is not possible to remove them, what will be the best step in order to fix this issue ?

also, how is it possible that it happens only in one indexer while i have indexer cluster with 3 peers? 

thanks

sarit

Labels (1)
Tags (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

This path keeps DataModel summary for prod index. Please check your accelerated data models which uses this prod index. In order to save disk space your can decrease acceleration time, i.e. if it is -1y, you can change to -6m or -3m depends on your needs. 

Another option is Rebalancing data in indexers from Cluster Master.

You should also check your event distribution between indexers. This problem shows your data sources for prod index somehow sending more data to this indexer. If these are Universal Forwarders, you can lower auto load balance setting to lower value and enable line breaker setting.

You can use information on below link;

https://lantern.splunk.com/hc/en-us/articles/1500000292062-Improving-event-distribution 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...