Knowledge Management

If my coldToFrozenDir is full or unavailable, do I lose my old data?

faol
Explorer

From can I see, Splunk continues to run but I would like to know what happens to the cold data which meets the criteria to be frozen? Once the frozen directory is made accessible, does Splunk continue to freeze the data, or was it already removed from the index?

0 Karma

bpaul_splunk
Splunk Employee
Splunk Employee

What occurs is the following.

  1. The script to move data to the frozen directory is run.
  2. There is no space to copy the data, or access is not available. This is logged in splunkd.log under the BucketMover category. The message will look something like the following. ERROR BucketMover - aborting move because recursive copy from src='/opt/splunk/var/lib/splunk/_internaldb/db/db_1435901691_1435696540_1132' to dst='/tmp/test/inflight-db_1435901691_1435696540_1132' failed (reason='Permission denied')
  3. The cold bucket is not removed.
  4. Once the issue preventing the script from freezing your data is resolved, the normal freezing process will resume.

If no action is taken to resolve the issue, the disk will eventually fill up and all indexing will stop.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...