Having a lot of jobs artifacts in the dispatch folder, is directly proportional to the number of search jobs, and the time to live of the search artifact (dispatch.ttl)
Knowing that you can look at your dispatch folder and figure what constitutes the mass of job artifacts.
Options to reduce the TTL are :
- edit the dispatch.ttl in savedsearch.conf. For a particular search, or in the generic settings.
- do the same on a per search basis using the UI > searches&reports > advanced edit
- reduce the ttl in alert_actions.conf
- or reduce the number of unnecessary alerts.
I get an error that says "Dispatch COmmand: The number of search artifacts in the dispatch directory is higher than recommended...."
I am just trying to figure out the best way to determine what is driving the large number of artifacts specifically. (Since we are running ITSI, I'm wondering what part of that, if any is contributing to the issue).