Splunk Search

Unable to see the License usage report "Could not create search"

khusain_splunk
Splunk Employee
Splunk Employee

I am not able to view my license usage report for Today and Previous 30 days. I am getting below WARNINGS under Message:

Dispatch Command: The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch.
Dispatch Command: The number of search artifacts in the dispatch directory is higher than recommended (count=25536, warning threshold = 5000) and could have an impact on search performance.

Tags (1)
0 Karma
1 Solution

khusain_splunk
Splunk Employee
Splunk Employee

It looks like dispatch directory hit the disk space threshold (5000MB). Please be informed that searches will not run until you fix this issue. You can go under "/opt/splunk/var/run/splunk/dispatch" directory and clear old search artifacts. If you can't delete anything from that directory then set the new threshold value for this parameter by navigating as follows:

Settings > Server settings > General settings > "Pause indexing if free disk space (in MB) falls below"

You can set it to 2000 or less than that also, then this error will go away and license and other searches will start running.

View solution in original post

0 Karma

khusain_splunk
Splunk Employee
Splunk Employee

It looks like dispatch directory hit the disk space threshold (5000MB). Please be informed that searches will not run until you fix this issue. You can go under "/opt/splunk/var/run/splunk/dispatch" directory and clear old search artifacts. If you can't delete anything from that directory then set the new threshold value for this parameter by navigating as follows:

Settings > Server settings > General settings > "Pause indexing if free disk space (in MB) falls below"

You can set it to 2000 or less than that also, then this error will go away and license and other searches will start running.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...