<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move index and resize in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140797#M28840</link>
    <description>&lt;P&gt;Thanks Iguinn,&lt;BR /&gt;
that worked ok with the exception of the limitation on the size. its currently at 150gb (original moved size) and hasnt gone down at all since i moved it yesterday.&lt;/P&gt;

&lt;P&gt;im investigating the splunkd.log now to see if i can pinpoint anything.&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2013 18:45:49 GMT</pubDate>
    <dc:creator>jrich523</dc:creator>
    <dc:date>2013-11-14T18:45:49Z</dc:date>
    <item>
      <title>Move index and resize</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140795#M28838</link>
      <description>&lt;P&gt;I have an Index which is on NAS. Im mostly having connection issues (win 2012R2 and Isilon NAS)&lt;/P&gt;

&lt;P&gt;so i was thinking about moving it local, restricting its size and using the NAS as Cold storage however i have a small problem that i dont want to figure out by testing.&lt;/P&gt;

&lt;P&gt;The index i'd like to move is currently about 200GB of data, I'd like to limit the warm on the new location (local to the server) to 50gb.&lt;/P&gt;

&lt;P&gt;so if i change the config file and move the files, when it starts up will it start to push that extra 150gb of files over ok?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2013 17:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140795#M28838</guid>
      <dc:creator>jrich523</dc:creator>
      <dc:date>2013-11-13T17:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Move index and resize</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140796#M28839</link>
      <description>&lt;P&gt;So, for my explanation, I am going to call your local drive &lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; and the NAS drive N:, and assume that the index is named myIndex&lt;/P&gt;

&lt;P&gt;I would do it this way: set up separate directories on &lt;span class="lia-unicode-emoji" title=":anguished_face:"&gt;😧&lt;/span&gt; &amp;amp; N: for the various parts of the indexes, copy in the data, edit indexes.conf&lt;/P&gt;

&lt;P&gt;1) Stop Splunk&lt;/P&gt;

&lt;P&gt;2) Create the directories on each drive (they can be named anything, actually) -&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;D:\Splunk\myIndex\db&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;D:\Splunk\myIndex\thaweddb&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;CODE&gt;N:\Splunk\myIndex\colddb&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;3) Find the &lt;CODE&gt;indexes.conf&lt;/CODE&gt; that currently contains the specifications for &lt;CODE&gt;myIndex&lt;/CODE&gt;. Make a backup copy of this file. Note the current locations of each directory in the file.&lt;/P&gt;

&lt;P&gt;4) Edit the following lines in 'indexes.conf'. This will set the new locations - and restrict the size of the hot/warm directory (&lt;CODE&gt;db&lt;/CODE&gt;). Notice that part of the &lt;CODE&gt;homepath&lt;/CODE&gt; space will be used by the hot buckets, but you can increase the size to account for that, of course. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[myIndex]
homePath = D:\Splunk\myIndex\db
coldPath = N:\Splunk\myIndex\colddb
thawedPath = D:\Splunk\myIndex\thaweddb
homePath.maxDataSizeMB = 50000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;5) Backup the current index. Copy/move the files from each of the old &lt;CODE&gt;db&lt;/CODE&gt;, &lt;CODE&gt;colddb&lt;/CODE&gt; and &lt;CODE&gt;thaweddb&lt;/CODE&gt; directories into the new locations. Be careful to &lt;STRONG&gt;maintain the file attributes&lt;/STRONG&gt; (ownership, permissions, etc) and to copy the whole directory tree.&lt;/P&gt;

&lt;P&gt;6) Restart Splunk.&lt;/P&gt;

&lt;P&gt;Everything should now be in its proper place and the new limitations on the size will take effect immediately, which means that Splunk will roll the warm buckets as quickly as possible to comply. You &lt;EM&gt;might&lt;/EM&gt; be able to manually move some warm buckets to cold - but you would have to carefully choose the buckets and it would probably be just as quick to let Splunk do it.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 06:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140796#M28839</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-11-14T06:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Move index and resize</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140797#M28840</link>
      <description>&lt;P&gt;Thanks Iguinn,&lt;BR /&gt;
that worked ok with the exception of the limitation on the size. its currently at 150gb (original moved size) and hasnt gone down at all since i moved it yesterday.&lt;/P&gt;

&lt;P&gt;im investigating the splunkd.log now to see if i can pinpoint anything.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 18:45:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140797#M28840</guid>
      <dc:creator>jrich523</dc:creator>
      <dc:date>2013-11-14T18:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Move index and resize</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140798#M28841</link>
      <description>&lt;P&gt;I'd check permissions on the directories, too. And another setting that might be helpful:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;maxWarmDBCount = 70&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This says that the maximum number of warm buckets is 70; if your default bucket size is 750 MB, this should work out to about 50 GB.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 20:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140798#M28841</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-11-14T20:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Move index and resize</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140799#M28842</link>
      <description>&lt;P&gt;Note that many times, for high volume indexes, the max size isn't met, so scaling the usage of the home path strictly by warm bucket count isn't always straightforward.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 20:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Move-index-and-resize/m-p/140799#M28842</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-11-14T20:18:27Z</dc:date>
    </item>
  </channel>
</rss>

