Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why is the Splunk dispatch directory not getting cleaned up automatically, even after setting the dispatch.ttl in savedsearches.conf?

$
0
0
We run into some issues in our Splunk environment. We have a Splunk 6.3 indexer and search head. The dispatch directory on the search head is constantly growing and Splunk stops working after a few days. We then need to manually restart the search head. After the restart, the dispatch directory is getting cleaned up automatically and only searches from the last 24h remain. I already set the dispatch.ttl in savedsearches.conf to 86400. (1 day) But the artifacts in the directory remain for much longer until we restart the system. We have about 10 scheduled searches with alarms which run every hour, so it is not that much. Is there any way to fix the automatic clean-up of the directory or what is the best way to restart the search head automatically every night on a Windows system?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>