Splunk Search

Why is /opt/splunk/var/run/searchpeers folder is filling up?

mbagali_splunk
Splunk Employee
Splunk Employee

Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers and this leads to filling up of /opt/splunk/

0 Karma
1 Solution

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

View solution in original post

mbagali_splunk
Splunk Employee
Splunk Employee

This is a known bug (SPL-140831) were Splunk dose not clean up $SPLUNK_HOME/var/run/searchpeers.

Affected splunk versions: 6.5.1,6.5.2,6.5.3,6.5.4,6.5.6,

Fixed version is : 6.5.6+

This issue is caused when a lookup exceeds the max_memtable_bytes settings in limits.conf.

Please refer below document for more details:

http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Limitsconf#.5Blookup.5D

Work around:

We need to Increase "max_memtable_bytes" under [lookup] inside limits.conf , so that the largest lookup won't get indexed.

nls7010
Path Finder

I am running version 7.2.6 and I have this issue as well. I did the search for lookups and did not get anything back. As far as I know, my customers are not using them at the moment. I am having a daily issue with disk space due to the bundles not being removed. Is there a way to keep the .bundle files down to only 3 at max at a time? Or something like that. I really don't want to have to delete the indexers (We have six) everytime we reach spacing issues.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Thanks for sharing. You should accept this as the answer so future Splunkers can see how to resolve the issue

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...