Splunk Search

Unable to see the License usage report "Could not create search"

khusain_splunk
Splunk Employee
Splunk Employee

I am not able to view my license usage report for Today and Previous 30 days. I am getting below WARNINGS under Message:

Dispatch Command: The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch.
Dispatch Command: The number of search artifacts in the dispatch directory is higher than recommended (count=25536, warning threshold = 5000) and could have an impact on search performance.

Tags (1)
0 Karma
1 Solution

khusain_splunk
Splunk Employee
Splunk Employee

It looks like dispatch directory hit the disk space threshold (5000MB). Please be informed that searches will not run until you fix this issue. You can go under "/opt/splunk/var/run/splunk/dispatch" directory and clear old search artifacts. If you can't delete anything from that directory then set the new threshold value for this parameter by navigating as follows:

Settings > Server settings > General settings > "Pause indexing if free disk space (in MB) falls below"

You can set it to 2000 or less than that also, then this error will go away and license and other searches will start running.

View solution in original post

0 Karma

khusain_splunk
Splunk Employee
Splunk Employee

It looks like dispatch directory hit the disk space threshold (5000MB). Please be informed that searches will not run until you fix this issue. You can go under "/opt/splunk/var/run/splunk/dispatch" directory and clear old search artifacts. If you can't delete anything from that directory then set the new threshold value for this parameter by navigating as follows:

Settings > Server settings > General settings > "Pause indexing if free disk space (in MB) falls below"

You can set it to 2000 or less than that also, then this error will go away and license and other searches will start running.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...