Splunk Search

Is there a permanent solution for handling too many search jobs found in the dispatch directory?

sunhoo
Engager

Hello.

I am getting this error:

Too many search jobs found in the dispatch directory (found=7079, warning level = 5000)

So I ran a script via CLI multiple times to delete all the search jobs in the dispatch folder, but it seems that it keeps repopulating back to ~7k search jobs the day after. Is there a permanent way to resolve this issue?
Thanks.

0 Karma

ppablo
Retired

Hi @sunhoo

There have been several questions in the forum on this very topic lately, but one of them has been particularly helpful. Check out the answers by sowings_splunk and yannK in this post:
https://answers.splunk.com/answers/213571/what-causes-too-many-search-jobs-found-in-the-disp.html

Here's the page from Splunk documentation that covers maintenance of the dispatch directory by tuning the TTL for different search artifacts:
http://docs.splunk.com/Documentation/Splunk/6.4.2/Search/Dispatchdirectoryandsearchartifacts#Dispatc...

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...