Reporting

How to determine what is filling up your index space

a212830
Champion

Hi,

I have an index(es) that are beginning to rapidly fill up my filesystems on a cluster. What is the quickest way to determine who the culprits are?

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

You can use firebrigade or dbinspect to see what indexes take up how much space in which buckets, and what your compression ratio is. You can use SoS or the new Distributed Management Console or the Licensing views to see what hosts, sourcetypes, etc. make up the most incoming data. Additionally, take cluster search and replication factors into account.

Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...