<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPLUNK_DB not being set in splunk-launch.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-DB-not-being-set-in-splunk-launch-conf/m-p/319921#M93657</link>
    <description>&lt;P&gt;OK it appears to be working, I am getting disk space used up, but its not the index data. the index data is behaving as it should and now going to the $SPLUNK_DB as specified in splunk-launch.conf, my bad.&lt;/P&gt;

&lt;P&gt;It looks like I have spool data taking up space, so I probably have a different issue to look at.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2017 12:00:32 GMT</pubDate>
    <dc:creator>neilhaywood</dc:creator>
    <dc:date>2017-12-05T12:00:32Z</dc:date>
    <item>
      <title>SPLUNK_DB not being set in splunk-launch.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-DB-not-being-set-in-splunk-launch-conf/m-p/319920#M93656</link>
      <description>&lt;P&gt;Splunk version 6.6.3&lt;/P&gt;

&lt;P&gt;We are running out of space for Hot/Warm data, so as a short term work around I am trying to get splunk to log HotWarm data under the colddb disk as we have lots of disk space there.&lt;/P&gt;

&lt;P&gt;dev1 /opt/splunk/var/       &amp;lt;&amp;lt;&amp;lt;&amp;lt; running out of space (This is where HotWarm goes)&lt;BR /&gt;
dev2 /opt/splunk/colddb/   &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; lots and lots of space (This is where cold data goes)&lt;BR /&gt;
created new location /opt/splunk/colddb/splunkdb  (owned by the splunk user, for the Hot/Warm data)&lt;/P&gt;

&lt;P&gt;I have stopped splunk, recursively copied over all the indexes (preserving permissions) to the new location, pointed SPLUNK_DB to it in splunk-launch.conf&lt;BR /&gt;
SPLUNK_DB=/opt/splunk/colddb/splunkdb/&lt;BR /&gt;
So we should use the device diskspace for cold data for hot/warm too under the splunkdb/&lt;/P&gt;

&lt;P&gt;...../local/indexes.conf uses the $SPLUNK_DB variable for the homePath's&lt;/P&gt;

&lt;P&gt;I then restarted splunk, but, $ echo $SPLUNK_DB still shows as /opt/splunk/var/lib/splunk and data of course still goes there.&lt;/P&gt;

&lt;P&gt;So my setting under splunk-launch.conf is not working.&lt;/P&gt;

&lt;P&gt;Further to that, we have splunk installed under a splunk user, under that users home directory is the .bash_profile, I can force SPLUNK_DB under there,&lt;BR /&gt;
echo $SPLUNK_DB then shows the correct path, YET! after restarting splunk, hot/warm data still logs to the default /opt/splunk/var/lib/splunk/&lt;/P&gt;

&lt;P&gt;Does anyone know why the setting in splunk-launch.conf would be overridden?&lt;BR /&gt;
And why the .bash_profile setting doesnt work either?&lt;BR /&gt;
I would use btool, but not sure how to for this problem.&lt;/P&gt;

&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-DB-not-being-set-in-splunk-launch-conf/m-p/319920#M93656</guid>
      <dc:creator>neilhaywood</dc:creator>
      <dc:date>2020-09-29T17:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: SPLUNK_DB not being set in splunk-launch.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-DB-not-being-set-in-splunk-launch-conf/m-p/319921#M93657</link>
      <description>&lt;P&gt;OK it appears to be working, I am getting disk space used up, but its not the index data. the index data is behaving as it should and now going to the $SPLUNK_DB as specified in splunk-launch.conf, my bad.&lt;/P&gt;

&lt;P&gt;It looks like I have spool data taking up space, so I probably have a different issue to look at.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 12:00:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SPLUNK-DB-not-being-set-in-splunk-launch-conf/m-p/319921#M93657</guid>
      <dc:creator>neilhaywood</dc:creator>
      <dc:date>2017-12-05T12:00:32Z</dc:date>
    </item>
  </channel>
</rss>

