Splunk Search

Why is /opt/splunk/var/run/searchpeers folder is filling up?

mbagali_splunk
Splunk Employee
Splunk Employee

Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers and this leads to filling up of /opt/splunk/

0 Karma
1 Solution

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

View solution in original post

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

nls7010
Path Finder

I am running version 7.2.6 and I have this issue as well. I did the search for lookups and did not get anything back. As far as I know, my customers are not using them at the moment. I am having a daily issue with disk space due to the bundles not being removed. Is there a way to keep the .bundle files down to only 3 at max at a time? Or something like that. I really don't want to have to delete the indexers (We have six) everytime we reach spacing issues.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Thanks for sharing. You should accept this as the answer so future Splunkers can see how to resolve the issue

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...