Deployment Architecture

Splunk stopped index. what is hot_v1_ID

moon92
New Member

Splunk stopped indexing when it sent message in splunkd.log

" WARN DatabaseDirectoryManager - Failed getting size of path='/splunk/splunk/var/lib/splunk/audit/db/hot_v1_592/1470663602-1470663601-4147689500280802279.tsidx.lock':No such file or directory "

What is the problem, and why?

Tags (3)
0 Karma

MuS
Legend

Hi moon92,

those are the hot buckets of your Splunk instance, see the docs for more details http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/HowSplunkstoresindexes#Bucket_names

Check for other errors before this message and check maybe your disk space usage. The is a default limit in server.conf of 5000mb, see docs for more details http://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Serverconf#Disk_usage_settings_.28for_the_in...

Beside this, it's hard to provide additional help based on the provided information.

Hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...