All Apps and Add-ons

The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch - But I have over 5 GB Free...

asbetsplunk
Explorer

Splunk single instance install on AWS.

Splunk Version: 6.3.0
Splunk Build: aa7d4b1ccb80

I am getting the error message, "The minimum free disk space (5000MB) reached for /opt/splunk/var/run/splunk/dispatch" however I have over 5 GB on my base install.

Also, had previously already moved all of my index data to a different volume before this error appeared.

See screenshots below - why am I getting this error and what do I need to do?

I'm assuming that I need to move the dispatch to my separate index volume but not understanding why I'm getting the error in the first place.

alt text alt text

0 Karma

vasanthmss
Motivator

Hi there,

Splunk required 5 GB in the required mount. with your configuration you installed in the tiny mount /dev/xvdal. Why don't you mount combine the same with /dev/xvdf. because the mount you were refereeing has lot of space. Is there any reason you were not installed in the /splunk_index_volume mount?

thanks,
V

V
0 Karma

asbetsplunk
Explorer

Thanks @vasanthmss for your reply.

I'm not sure I understand - yes, the mount is small but it is larger than 5 GB so why is the error generating? If the free space /dev/xvda1 was 4.9 GB or exactly 5 GB then I completely understand.

The reason why the first partition is small is because the AWS Enterprise instance offered in the AWS Marketplace defaults to 8 GB. I kept that size and added another volume for index data because well, obviously 8 GB minus a Splunk install isn't going to be enough for anything.

Unfortunately, I didn't know that there is another file (i.e. ./dispatch) that grows in size as well (I'm assuming - still have minimum free space so don't get it) - that is why I didn't know that I needed to move it.

For now I reduced the minimum free disk space threshold to 4 GB so I can at least search.

  1. Is there a way to safely move the dispatch file using the command line? I'm asking because I see references to symbolic links that some say worked and others didn't. https://answers.splunk.com/answers/2205/can-i-change-the-path-of-the-dispatch-directory.html#answer-...
  2. Are there any other "gotchas" like this that we should be aware of?
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...