Splunk Search

What exactly is Archiver (Archiving large_file) doing?

the_wolverine
Champion

In splunkd.log we see:

01-31-2019 12:38:03.683 -0800 INFO Archiver - Archiving large_file=/opt/splunk/etc/apps/search/lookups/large_lookup.csv of size_in_bytes=262621937 (exceeding threshold=52428800)

This is actually useful for finding out how large lookup files are. What is Splunk actually doing with it?

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

HI @the_wolverine

The archiver process goes through your search head knowledge objects (such as lookups) and bundles them into a tar file so they can be sent to the indexers. Its good to keep your bundle size small as possible so this is ujst an informational message to say there is a large file. If it is not needed then you should delete it or add it to the replicationBlacklist of distsearch.conf

Cheers

dkeck
Influencer

This is simply informing you that the lookup is larger than the max 50mb individual file size in a knowledge bundle

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...