All Apps and Add-ons

tsidxstats for pan_traffic very large

chuffpdx
New Member

On the search head:
du -sh /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/
183G /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/

Any ideas on how to keep this in check?

0 Karma

btorresgil
Builder

Hi chuffpdx,

With the version of the App you're using, there is no built-in way to keep these files in check. This is a limitation of the TSIDX system from Splunk 5. You can remove the files manually... shut down splunk, remove the pan_* directories, then start splunk. You can write a script to do this periodically, but it will prevent historic data from begin visible in the dashboards of the app if you remove the files, because you're deleting that historic data.

Starting with version 4.1 of the Palo Alto Networks App, it uses the new Splunk 6 datamodel feature instead of TSIDX. The datamodel automatically limits the amount of historic data in the summary index to an amount you specify (1 year by default). If you upgrade to Splunk 6 and Palo Alto Networks app version 4.1 or higher, then you won't have these TSIDX files anymore.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...