Splunk Search

What exactly is Archiver (Archiving large_file) doing?

the_wolverine
Champion

In splunkd.log we see:

01-31-2019 12:38:03.683 -0800 INFO Archiver - Archiving large_file=/opt/splunk/etc/apps/search/lookups/large_lookup.csv of size_in_bytes=262621937 (exceeding threshold=52428800)

This is actually useful for finding out how large lookup files are. What is Splunk actually doing with it?

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

HI @the_wolverine

The archiver process goes through your search head knowledge objects (such as lookups) and bundles them into a tar file so they can be sent to the indexers. Its good to keep your bundle size small as possible so this is ujst an informational message to say there is a large file. If it is not needed then you should delete it or add it to the replicationBlacklist of distsearch.conf

Cheers

dkeck
Influencer

This is simply informing you that the lookup is larger than the max 50mb individual file size in a knowledge bundle

0 Karma
Get Updates on the Splunk Community!

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

AI Adoption Hub Launch | Curated Resources to Get Started with AI in Splunk

Hey Splunk Practitioners and AI Enthusiasts! It’s no secret (or surprise) that AI is at the forefront of ...