Splunk IT Service Intelligence
Highlighted

huge waitomo.log file

Explorer

We see ~5GB log file in var\log\splunk folder of our Splunk Insights for Infrastructure installation. It is growing. What is this file? We googled about this file but no information is found.

Highlighted

Re: huge waitomo.log file

Splunk Employee
Splunk Employee

Hi s2801871r!

Can you provide some info around where/how you deployed (ami? tarball?) and what version you are on?

I believe it could be debug/app logs not being rolled. likely safe to reap to regain the space and add to logrotate.

0 Karma
Highlighted

Re: huge waitomo.log file

Explorer

We are running on Windows server 2012 R2. Following are the SII version details. There are lot of INFO messages in that file. I did not find any config set up related to this file waitomo.log. It looks like WAITOMO is a Splunk project. There is some info I got while googling. Any ideas?

Splunk Insights For Infrastructure

Version ..................................................................................1.1.0
Build ..................................................................................2
Server ..................................................................................4 CPU 8 GB RAM
Splunk TA AWS Version ..................................................................................4.5.0
Splunk Version ..................................................................................7.1.0
Splunk Build ..................................................................................cc33fbdac2cf

0 Karma
Highlighted

Re: huge waitomo.log file

Splunk Employee
Splunk Employee

Looks like a similar bug was marked fixed in 1.2.

waitomo was the project name, I assume it's the log being referenced in this bug, but by it's GA name.

SII-2878 splunk_app_infra.log is not being rotated.

http://docs.splunk.com/Documentation/Infrastructure/1.2.0/ReleaseNotes/Fixedissues

I'd recommend upgrade or just add to logrotate rules on the box.

Highlighted

Re: huge waitomo.log file

Explorer

Great. Thanks for the info. Can you please provide guidance on how to add the logrotation for this file? Which configuration file should be updated? Appreciate it. We will plan for upgrade.

0 Karma
Highlighted

Re: huge waitomo.log file

Splunk Employee
Splunk Employee

I would probably just stop splunk, archive the log, delete it, then restart Splunk. Then monitor it till upgrade.

Do you have a Splunk support contract?

It would be good to sync with support on this one.

0 Karma