Knowledge Management

If my coldToFrozenDir is full or unavailable, do I lose my old data?

faol
Explorer

From can I see, Splunk continues to run but I would like to know what happens to the cold data which meets the criteria to be frozen? Once the frozen directory is made accessible, does Splunk continue to freeze the data, or was it already removed from the index?

0 Karma

bpaul_splunk
Splunk Employee
Splunk Employee

What occurs is the following.

  1. The script to move data to the frozen directory is run.
  2. There is no space to copy the data, or access is not available. This is logged in splunkd.log under the BucketMover category. The message will look something like the following. ERROR BucketMover - aborting move because recursive copy from src='/opt/splunk/var/lib/splunk/_internaldb/db/db_1435901691_1435696540_1132' to dst='/tmp/test/inflight-db_1435901691_1435696540_1132' failed (reason='Permission denied')
  3. The cold bucket is not removed.
  4. Once the issue preventing the script from freezing your data is resolved, the normal freezing process will resume.

If no action is taken to resolve the issue, the disk will eventually fill up and all indexing will stop.

Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...