Hello Splunk Community, I am running Splunk Enterprise Version: 9.2.3 Steps to reproduce: Make a config change to an app on the Cluster Manager - $SPLUNK_HOME/etc/master-apps/<custom_app>/local/indexes.conf Validate and Check Restart from Cluster Manager GUI. Bundle Information: Updated Time shows a date/time from last month (did not update) The Active Bundle ID did not change Unable to make changes to apps and have them pushed to Indexers. Note: there are other issues All three of my clustered Indexers are in Automatic Detention Seeing these Messages on GUI: Search peer xxx has the following message: The minimum free disk space (1000MB) reached for /opt/splunk/var/run/splunk/dispatch. Search peer xxx has the following message: Now skipping indexing of internal audit events, because the downstream queue is not accepting data. Will keep dropping events until data flow resumes. Review system health: ensure downstream indexing and/or forwarding are operating correctly Ultimatley, I am trying to push changes to the setting frozenTimePeriodInSecs to reduce stored logs and free up space. Thanks for your help
... View more