Deployment Architecture

default.old directories in SHC

strive
Influencer

Hi,

There are thousands of default.old.<date-time> directories under /opt/splunk/etc/apps/<app_name>/

There was similar thread in this forum - https://answers.splunk.com/answers/236307/search-head-cluster-defaultold-directories.html
According to this it should have been fixed in 6.6. But i do not see this in list of Fixed Issues for that version.

Has this issue been resolved? If yes, in which version?

Thanks,
Strive

Tags (2)
0 Karma

skalliger
Motivator

Hi,

I am not sure that this is really a bug. Because this behaviour has been around for quite some time now. Those are simply backup directories which can be deleted manually.

What I think the Splunk employee was actually referring to, was this bug:
Splunk not cleaning up $SPLUNK_HOME/var/run/searchpeers of .delta files and matching directories whose only non-empty subdirectory has the .index extension
..which has been fixed in version 6.6.3.

Neither have I seen any known issue related to this (http://docs.splunk.com/Documentation/Splunk/6.6.5/ReleaseNotes/Knownissues).

Skalli

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...