After upgrading to Splunk version 6.2.4, the $SPLUNK_HOME/var/spool/splunk/ directory starts filling up with files with the extension of .stash_new. This [answers post][1] has been reviewed, but the issue should have been fixed in version 5.0.3. Why is this occurring?
[1]: http://answers.splunk.com/answers/123825/how-to-clean-stash-new-files-from-the-spool-directory.html?utm_source=typeahead&utm_medium=newquestion&utm_campaign=no_votes_sort_relev
↧