Hi,
There are thousands of default.old.<date-time>
directories under /opt/splunk/etc/apps/<app_name>/
There was similar thread in this forum - https://answers.splunk.com/answers/236307/search-head-cluster-defaultold-directories.html
According to this it should have been fixed in 6.6. But i do not see this in list of Fixed Issues for that version.
Has this issue been resolved? If yes, in which version?
Thanks,
Strive
Hi,
I am not sure that this is really a bug. Because this behaviour has been around for quite some time now. Those are simply backup directories which can be deleted manually.
What I think the Splunk employee was actually referring to, was this bug:
Splunk not cleaning up $SPLUNK_HOME/var/run/searchpeers of .delta files and matching directories whose only non-empty subdirectory has the .index extension
..which has been fixed in version 6.6.3.
Neither have I seen any known issue related to this (http://docs.splunk.com/Documentation/Splunk/6.6.5/ReleaseNotes/Knownissues).
Skalli