Monitoring Splunk

The index processor has paused data flow

rgarcia
Engager

After a hardware failure was resolved, I attempted to start splunk again...but I am now getting this error

"The index processor has paused data flow. Current free disk space on partition '/' has fallen to 158MB, below the minimum of 5000MB. Data writes to index path '/data1/splunk/indexes/audit/db'cannot safely proceed. Increase free disk space on partition '/' by removing or relocating data."

I understand what is saying, but the odd part is that partition "/" never had that much space and all other indexers are configured the same with no issues.

What am I missing here?

Labels (3)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Can it be so that your node hasn’t mount all FSs yet?

You should check what is your SPLUNK_DB path and then check that it’s present and it has enough space.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Can it be so that your node hasn’t mount all FSs yet?

You should check what is your SPLUNK_DB path and then check that it’s present and it has enough space.

r. Ismo

0 Karma

rgarcia
Engager

You're right, mount points were missing. thank you

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...