Splunk Search

How do I fix low disk space in Enterprise indexer?

Fields29
New Member

How do I fix low disk space in enterprise indexer.

Please comment back on how to fix.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

There are two ways: 1) Add more disks; 2) delete some data.

There are many ways to reduce disk space use.  If the $SPLUNK_DB space is shared with the OS or $SPLUNK_HOME (both bad ideas) then use the du utility to determine what is using up disk space and correct as necessary.

Check for old bundles and delete them.

You'll get the most return, however, by reducing indexed data.  Reduce the frozenTimePeriodInSecs setting (it defaults to 7 years) for one or more of your indexes and restart the indexer.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...