Our search heads are filling up with tsidx files in the /var/run/splunk/dispatch/tsidxstats directory, but I am not able to find any documentation that explains what these files are. We suspect that they are search artifacts/results, but could this be summarized data?
I know that the location of these files can be changed in the indexes.conf, but I am unsure what they are and large they can be. We have seen as much as 600GB on one search head. I can resize the space we have alloted for our search head, but I have no idea how big it needs to be.
... View more