Splunk Enterprise

Wrong volume usage reported on monitoring console and "_introspection" index

Path Finder


I have a volume with a filesystem mountpoint as VolumePath.

The page "volume Detail: Instance" on monitoring console say me that the "volume usage" on this volume is ~26'400GB but the "df" command on operating system say me that the usage is ~21'416GB

I have enabled "tsidxreduction" recently.

Any Idee why do I have a about 5TB more by Splunk usage as by Filesystem usage?

Labels (2)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!