<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Indexes data pointing to different storage in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750833#M22773</link>
    <description>&lt;P&gt;You've just stumbled across SmartStore (S2).&amp;nbsp; S2 keeps hot buckets local and copies warm buckets to S3.&amp;nbsp; A cache of roughly 30 days of data is retained locally for faster search performance.&lt;/P&gt;&lt;P&gt;To implement S2 correctly, see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/AboutSmartStore" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/AboutSmartStore&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 31 Jul 2025 18:04:21 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2025-07-31T18:04:21Z</dc:date>
    <item>
      <title>Splunk Indexes data pointing to different storage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750827#M22772</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I want to point the secondary storage of my splunk indexer to mix with another storage, like point it to cloud storage?&lt;BR /&gt;&lt;BR /&gt;so it will like this one is the common:&lt;/P&gt;&lt;PRE&gt;[volume:hot1]
path = /mnt/fast_disk
maxVolumeDataSizeMB = 100000&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;PRE&gt;[volume:s3volume]
storageType = remote
path = s3://&amp;lt;bucketname&amp;gt;/rest/of/path&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a mechanism or reference to did this?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2025 16:47:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750827#M22772</guid>
      <dc:creator>elend</dc:creator>
      <dc:date>2025-07-31T16:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes data pointing to different storage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750833#M22773</link>
      <description>&lt;P&gt;You've just stumbled across SmartStore (S2).&amp;nbsp; S2 keeps hot buckets local and copies warm buckets to S3.&amp;nbsp; A cache of roughly 30 days of data is retained locally for faster search performance.&lt;/P&gt;&lt;P&gt;To implement S2 correctly, see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/AboutSmartStore" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/AboutSmartStore&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2025 18:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750833#M22773</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-07-31T18:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes data pointing to different storage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750841#M22776</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254178"&gt;@elend&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can configure Splunk (since 7.2 I think) to use mixture of local storage and S3-compliant storage, including the likes of Amazon S3 using Splunk's SmartStore functionality, this essentially uses your local storage for hot buckets and as a local cache for buckets which are also stored in S3. Its more of a complex beast than I can go into here, and there are lots of things to consider - for example this is generally considered a one-way exercise!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/SmartStore" target="_blank"&gt;https://docs.splunk.com/Documentation/SVA/current/Architectures/SmartStore&lt;/A&gt;&amp;nbsp;gives a good overview of the architecture, benefits and next steps.&lt;/P&gt;&lt;P&gt;Check out&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.3/manage-smartstore/configure-smartstore" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.3/manage-smartstore/configure-smartstore&lt;/A&gt;&amp;nbsp;for more info on setting up smartstore as well as&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.4/deploy-smartstore/deploy-smartstore-on-a-new-standalone-indexer" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise/administer/manage-indexers-and-indexer-clusters/9.4/deploy-smartstore/deploy-smartstore-on-a-new-standalone-indexer&lt;/A&gt;&amp;nbsp;which has some info on setting this up on a single indexer (as a starter, this will depend on your specific environment architecture).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 31 Jul 2025 18:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750841#M22776</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-31T18:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes data pointing to different storage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750875#M22777</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254178"&gt;@elend&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; mentioned,&lt;BR /&gt;This is exactly what SmartStore is designed for.&lt;/P&gt;&lt;P&gt;Hot buckets stay on local disk for fast ingestion and search and warm buckets are offloaded to remote storage (e.g., S3).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#&lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/SmartStore" target="_blank"&gt;https://docs.splunk.com/Documentation/SVA/current/Architectures/SmartStore&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 04:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750875#M22777</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-08-01T04:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes data pointing to different storage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750885#M22778</link>
      <description>&lt;P&gt;Oh thankyou. so thats just point the bucket like the sample right?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 06:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750885#M22778</guid>
      <dc:creator>elend</dc:creator>
      <dc:date>2025-08-01T06:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Indexes data pointing to different storage</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750900#M22779</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254178"&gt;@elend&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You configure a volume in your indexes.conf which is your s3 location essentially, and then you can update all or individual indexes to use that volume by setting the remotePath eg&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;remotePath = volume:&amp;lt;VOLUME_NAME&amp;gt;/$_index_name&lt;/PRE&gt;&lt;P&gt;the $_index_name is actually an internal variable so you don’t need to overwrite this.&lt;BR /&gt;in addition to the other docs I posted on the previous post it’s worth checking&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/SmartStoresecuritystrategies" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/SmartStoresecuritystrategies&lt;/A&gt; too.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you? If so, please consider&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Aug 2025 07:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Indexes-data-pointing-to-different-storage/m-p/750900#M22779</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-08-01T07:38:00Z</dc:date>
    </item>
  </channel>
</rss>

