Splunk Search

Minimum free disk space reached for /opt/splunk/var/run/dispatch

splunkingsplun1
Explorer

I am receiving the following message in Splunk 6.01 "Minimum free disk space reached (5000MB) for /opt/splunk/var/run/dispatch". We also have Splunk App for ES installed. I have erased everything in the directory and after one day I receive the message again. What do I need to adjust in order to resolve this issue permanently?

Tags (3)

sherm77
Path Finder

I had this issue installing a heavy forwarder, I was allocated 4gb of space and after the install, I only had 3.4gb left.

After researching it, I added this to my ~/etc/system/local/server.conf:

[diskUsage]
minFreeSpace =2000

Yes, this is low, but I'm just receiving & forwarding, and not expecting to index anything relevant here. If I run into space issues, I'll just request a few more gigs of space.

mkinsley_splunk
Splunk Employee
Splunk Employee

5GB is dangerously low for an enterprise system. After you optimize the TTL on your results , you may still find yourself running low on space.

See about attaching more space to your system. One of the great things about *NIX systems is that you can mount new storage directly to your var/run/dispatch directory without affecting the rest of your system.

Also if your system is using LVM volumes you can also transparently add storage without interruption.

Good luck

linu1988
Champion

Moreover, whichever jobs are not required you could set dispatch.ttl parameter to as low as possible.

rahulroy_splunk
Path Finder
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...