Getting Data In

Will deleting the fish bucket file cause forwarder to send all the old data that is already indexed?

spl_unker
Explorer

Hi ,

In one of the OLD UF,  fish bucket has occupied the complete disk space and service has been stopped.  will deleting the fish bucket file cause forwarder to send all the old data that is already indexed ?

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

yes, all the log files still present in the system and reachable by the inputs.conf stanzas will be indexed again.

Probably the only way is to give more space to the Splunk partition.

Ciao.

Giuseppe

View solution in original post

spl_unker
Explorer

Thanks for the confirmation @gcusello 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @spl_unker,

yes, all the log files still present in the system and reachable by the inputs.conf stanzas will be indexed again.

Probably the only way is to give more space to the Splunk partition.

Ciao.

Giuseppe

impurush
Contributor

Hi @gcusello,

Is there any mechanism to clear the entries from the fish bucket after some time or let's say if I set the limit in the fish bucket,  which part of the fish bucket gets reduced to like 1 GB fish bucket, and if I set 500 MB and what would be deleted?

Increasing the space for the fish bucket is not the solution I am looking for because it may not have the entries from the old as the retention period in the server is less but the number of rotated files is more.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @impurush,

you can find how to clean the fishbucket in this answer https://community.splunk.com/t5/Getting-Data-In/How-to-reindex-data-from-a-forwarder/m-p/93310

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...