On the search head:
du -sh /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/
183G /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/
Any ideas on how to keep this in check?
Hi chuffpdx,
With the version of the App you're using, there is no built-in way to keep these files in check. This is a limitation of the TSIDX system from Splunk 5. You can remove the files manually... shut down splunk, remove the pan_* directories, then start splunk. You can write a script to do this periodically, but it will prevent historic data from begin visible in the dashboards of the app if you remove the files, because you're deleting that historic data.
Starting with version 4.1 of the Palo Alto Networks App, it uses the new Splunk 6 datamodel feature instead of TSIDX. The datamodel automatically limits the amount of historic data in the summary index to an amount you specify (1 year by default). If you upgrade to Splunk 6 and Palo Alto Networks app version 4.1 or higher, then you won't have these TSIDX files anymore.