Splunk Search

Why is /opt/splunk/var/run/searchpeers folder is filling up?

mbagali_splunk
Splunk Employee
Splunk Employee

Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers and this leads to filling up of /opt/splunk/

0 Karma
1 Solution

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

View solution in original post

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

nls7010
Path Finder

I am running version 7.2.6 and I have this issue as well. I did the search for lookups and did not get anything back. As far as I know, my customers are not using them at the moment. I am having a daily issue with disk space due to the bundles not being removed. Is there a way to keep the .bundle files down to only 3 at max at a time? Or something like that. I really don't want to have to delete the indexers (We have six) everytime we reach spacing issues.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Thanks for sharing. You should accept this as the answer so future Splunkers can see how to resolve the issue

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...