All Apps and Add-ons

How to resolve error "Search not executed: The minimum free disk space (50000MB) reached" after clearing the dispatch folder?

urapaveerapan
Explorer

Dear guys,

I got an error "Search not executed: The minimum free disk space (50000MB) reached for /opt/splunk/var/run/splunk/dispatch"

I've tried several suggestions but it's not working such as
1. Increase/Decrease number in "Pause indexing if free disk space (in MB)" and restart the Splunk
2. Clear data in dispatch folder by delete in Jobs. Now the dispatch folder contains just 4.6M

However the error still shows and I cannot search any data. Please help.

0 Karma
1 Solution

urapaveerapan
Explorer

I finally got the solution.

The disk space is too low.
If you use linux, You can check it by type "df -h"
For me, the available space in /dev/mapper/system-opt is lower than what I set in "Pause indexing if free disk space (in MB)".

As a workaround, I set "Pause indexing if free disk space (in MB)" is be lower than the available disk. Then the solution is to increase the disk space.

View solution in original post

0 Karma

urapaveerapan
Explorer

I finally got the solution.

The disk space is too low.
If you use linux, You can check it by type "df -h"
For me, the available space in /dev/mapper/system-opt is lower than what I set in "Pause indexing if free disk space (in MB)".

As a workaround, I set "Pause indexing if free disk space (in MB)" is be lower than the available disk. Then the solution is to increase the disk space.

0 Karma

ddrillic
Ultra Champion
0 Karma

urapaveerapan
Explorer

Thank you.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...