<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer _internal size under /opt/splunk/var/lib is large in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478219#M82096</link>
    <description>&lt;P&gt;Can you let me know if there is any difference in indexes.conf between _internal index and other indexes which is why they are going to your actual path.&lt;BR /&gt;
yes, if you add Splunk_DB path it will apply to all the indexes.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 02:52:28 GMT</pubDate>
    <dc:creator>sathwikr076</dc:creator>
    <dc:date>2020-09-30T02:52:28Z</dc:date>
    <item>
      <title>Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478216#M82093</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have an indexer cluster that has a custom indexes.conf that specifies the volume path and retention of each index. &lt;BR /&gt;
However, it appears the _internal DB on each of the indexers it writing to  &lt;CODE&gt;/opt/splunk/var/lib&lt;/CODE&gt; instead of our custom volume where all the other indexes are writing. This is causing our  &lt;CODE&gt;/opt/splunk&lt;/CODE&gt; filesystem to fill up. &lt;/P&gt;

&lt;P&gt;Can someone explain why the indexers are not sending their  &lt;CODE&gt;_internaldb logs to /opt/splunk_hot&lt;/CODE&gt; even though we are referencing the volume in _internal? The ellipses are all the other indexes in the indexes.conf&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;indexes.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# VOLUME SETTINGS
# One Volume for Hot and Cold
[volume:primary]
path = /opt/splunk_hot

[volume:secondary]
path = /opt/splunk_cold
....
[_internal]
repFactor = auto
homePath   = volume:primary/_internal/db
coldPath   = volume:secondary/_internaldb/colddb
thawedPath = /opt/splunk_cold/_internaldb/thaweddb
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 04 Nov 2019 13:59:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478216#M82093</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2019-11-04T13:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478217#M82094</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;did you mention your primary volume path at /opt/splunk/etc/splunk-launch.conf. if you did not mention your path their, the buckets will go to the default location which is /opt/splunk/var/lib/splunk.&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 16:14:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478217#M82094</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-11-04T16:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478218#M82095</link>
      <description>&lt;P&gt;Hey, i had no idea about this setting. So if i put the &lt;EM&gt;SPLUNK_DB&lt;/EM&gt; path to /opt/splunk_hot, will that affect any of my other indexes? Keep in mind, all indexes excluding &lt;EM&gt;_internal&lt;/EM&gt; are correctly sending to /opt/splunk_hot. I would've assume explicitly setting the path's above (which are not referencing &lt;EM&gt;SPLUNK_DB&lt;/EM&gt;) woulve work...&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:52:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478218#M82095</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2020-09-30T02:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478219#M82096</link>
      <description>&lt;P&gt;Can you let me know if there is any difference in indexes.conf between _internal index and other indexes which is why they are going to your actual path.&lt;BR /&gt;
yes, if you add Splunk_DB path it will apply to all the indexes.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:52:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478219#M82096</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2020-09-30T02:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478220#M82097</link>
      <description>&lt;P&gt;I guess there is another config file somewhere that takes precedence. Try btool to see what the effective configuration is for that index and what file it comes from.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 15:47:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478220#M82097</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2019-11-08T15:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478221#M82098</link>
      <description>&lt;P&gt;Assuming the config you provided is what you've actually deployed, the answer is hiding in plain sight &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;There is an error in your homePath declaration.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; homePath   = volume:primary/_internal/db
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Should be:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; homePath   = volume:primary/_internaldb/db
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 08 Nov 2019 22:55:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478221#M82098</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-11-08T22:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478222#M82099</link>
      <description>&lt;P&gt;Hey, thanks for the reply. However, Splunk doesn't care what the name of the directory is as long as that directory never changes. When an index is created using &lt;STRONG&gt;[],&lt;/STRONG&gt; Splunk knows to write and read data from the directory paths specified under this stanza. &lt;/P&gt;

&lt;P&gt;The solution to my problem was what &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161028"&gt;@sathwikr076&lt;/a&gt; mentioned. By changed the DB_PATH under  &lt;EM&gt;/opt/splunk/etc/splunk-launch.conf,&lt;/EM&gt; data for the &lt;STRONG&gt;_internal&lt;/STRONG&gt; index began writing to splunk_hot like anticipated.&lt;/P&gt;

&lt;P&gt;Thank you for your response though!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:56:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478222#M82099</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2020-09-30T02:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer _internal size under /opt/splunk/var/lib is large</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478223#M82100</link>
      <description>&lt;P&gt;Ah, good to know! And glad you got it resolved!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 14:59:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-internal-size-under-opt-splunk-var-lib-is-large/m-p/478223#M82100</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2019-11-11T14:59:07Z</dc:date>
    </item>
  </channel>
</rss>

