Splunk Search

Why is /opt/splunk/var/run/searchpeers folder is filling up?

mbagali_splunk
Splunk Employee
Splunk Employee

Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers and this leads to filling up of /opt/splunk/

0 Karma
1 Solution

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

View solution in original post

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

nls7010
Path Finder

I am running version 7.2.6 and I have this issue as well. I did the search for lookups and did not get anything back. As far as I know, my customers are not using them at the moment. I am having a daily issue with disk space due to the bundles not being removed. Is there a way to keep the .bundle files down to only 3 at max at a time? Or something like that. I really don't want to have to delete the indexers (We have six) everytime we reach spacing issues.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Thanks for sharing. You should accept this as the answer so future Splunkers can see how to resolve the issue

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 2)

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Index This | I am a number but I am countless. What am I?

January 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  Happy New Year! We’re ...

What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience

PLATFORM TECH TALKS What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience Thursday, February 27, ...