Splunk Search

What exactly is Archiver (Archiving large_file) doing?

the_wolverine
Champion

In splunkd.log we see:

01-31-2019 12:38:03.683 -0800 INFO Archiver - Archiving large_file=/opt/splunk/etc/apps/search/lookups/large_lookup.csv of size_in_bytes=262621937 (exceeding threshold=52428800)

This is actually useful for finding out how large lookup files are. What is Splunk actually doing with it?

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

HI @the_wolverine

The archiver process goes through your search head knowledge objects (such as lookups) and bundles them into a tar file so they can be sent to the indexers. Its good to keep your bundle size small as possible so this is ujst an informational message to say there is a large file. If it is not needed then you should delete it or add it to the replicationBlacklist of distsearch.conf

Cheers

dkeck
Influencer

This is simply informing you that the lookup is larger than the max 50mb individual file size in a knowledge bundle

0 Karma
Get Updates on the Splunk Community!

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...