All Apps and Add-ons

tsidxstats for pan_traffic very large

chuffpdx
New Member

On the search head:
du -sh /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/
183G /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/

Any ideas on how to keep this in check?

0 Karma

btorresgil
Builder

Hi chuffpdx,

With the version of the App you're using, there is no built-in way to keep these files in check. This is a limitation of the TSIDX system from Splunk 5. You can remove the files manually... shut down splunk, remove the pan_* directories, then start splunk. You can write a script to do this periodically, but it will prevent historic data from begin visible in the dashboards of the app if you remove the files, because you're deleting that historic data.

Starting with version 4.1 of the Palo Alto Networks App, it uses the new Splunk 6 datamodel feature instead of TSIDX. The datamodel automatically limits the amount of historic data in the summary index to an amount you specify (1 year by default). If you upgrade to Splunk 6 and Palo Alto Networks app version 4.1 or higher, then you won't have these TSIDX files anymore.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...