Splunk Search

Unable to see the License usage report "Could not create search"

khusain_splunk
Splunk Employee
Splunk Employee

I am not able to view my license usage report for Today and Previous 30 days. I am getting below WARNINGS under Message:

Dispatch Command: The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch.
Dispatch Command: The number of search artifacts in the dispatch directory is higher than recommended (count=25536, warning threshold = 5000) and could have an impact on search performance.

Tags (1)
0 Karma
1 Solution

khusain_splunk
Splunk Employee
Splunk Employee

It looks like dispatch directory hit the disk space threshold (5000MB). Please be informed that searches will not run until you fix this issue. You can go under "/opt/splunk/var/run/splunk/dispatch" directory and clear old search artifacts. If you can't delete anything from that directory then set the new threshold value for this parameter by navigating as follows:

Settings > Server settings > General settings > "Pause indexing if free disk space (in MB) falls below"

You can set it to 2000 or less than that also, then this error will go away and license and other searches will start running.

View solution in original post

0 Karma

khusain_splunk
Splunk Employee
Splunk Employee

It looks like dispatch directory hit the disk space threshold (5000MB). Please be informed that searches will not run until you fix this issue. You can go under "/opt/splunk/var/run/splunk/dispatch" directory and clear old search artifacts. If you can't delete anything from that directory then set the new threshold value for this parameter by navigating as follows:

Settings > Server settings > General settings > "Pause indexing if free disk space (in MB) falls below"

You can set it to 2000 or less than that also, then this error will go away and license and other searches will start running.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...