All Apps and Add-ons

tsidxstats for pan_traffic very large

chuffpdx
New Member

On the search head:
du -sh /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/
183G /opt/splunk/var/lib/splunk/tsidxstats/pan_traffic/

Any ideas on how to keep this in check?

0 Karma

btorresgil
Builder

Hi chuffpdx,

With the version of the App you're using, there is no built-in way to keep these files in check. This is a limitation of the TSIDX system from Splunk 5. You can remove the files manually... shut down splunk, remove the pan_* directories, then start splunk. You can write a script to do this periodically, but it will prevent historic data from begin visible in the dashboards of the app if you remove the files, because you're deleting that historic data.

Starting with version 4.1 of the Palo Alto Networks App, it uses the new Splunk 6 datamodel feature instead of TSIDX. The datamodel automatically limits the amount of historic data in the summary index to an amount you specify (1 year by default). If you upgrade to Splunk 6 and Palo Alto Networks app version 4.1 or higher, then you won't have these TSIDX files anymore.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...