<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexing problems in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Indexing-problems/m-p/596532#M11518</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245432"&gt;@AntoineDRN&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to set the $SPLUNK_DB variable on Indexers in &lt;STRONG&gt;$SPLUNK_HOME/etc/splunk-launch.conf&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;you should find it commented, you have to uncomment it and use the correct folder where indexes are located,&lt;/P&gt;&lt;P&gt;by default it's &lt;STRONG&gt;$SPLUNK_HOME/var/lib/splunk&lt;/STRONG&gt;, in your case it should be &lt;STRONG&gt;/dev/vda1&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Then, you have to insert in each path that you find in each indexes,conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[index_name]
coldPath = $SPLUNK_DB\index_name\colddb
homePath = $SPLUNK_DB\index_name\db
thawedPath = $SPLUNK_DB\index_name\thaweddb&lt;/LI-CODE&gt;&lt;P&gt;Remember to restart Splunk after conf files upgrade.&lt;/P&gt;&lt;P&gt;In this way the indexes.conf files address the correct folders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 05 May 2022 14:25:44 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-05-05T14:25:44Z</dc:date>
    <item>
      <title>Indexing problems</title>
      <link>https://community.splunk.com/t5/Installation/Indexing-problems/m-p/596528#M11517</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;/P&gt;&lt;P&gt;I'm pretty new with Splunk and I retrieve an old splunk project that i didn't set up at all. I'm trying to train myself on it, but... I have some problems i couldn't solve alone.&lt;/P&gt;&lt;P&gt;I have one Search Head, one Indexer and between 3 and 5 forwarders depending on my need.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the VM of my indexer :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AntoineDRN_0-1651758804401.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19447iB339963343F219E1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AntoineDRN_0-1651758804401.png" alt="AntoineDRN_0-1651758804401.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Almost all logs that I collected went in /dev/vda1, which is not suppose to be the case. I've override the default storage location , but i guess it doesn't matter ...&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/system/local/indexes.conf&amp;nbsp; &amp;nbsp;:&lt;/P&gt;&lt;P&gt;[main]&lt;BR /&gt;homePath = /mnt/data/$_index_name/db&lt;/P&gt;&lt;P&gt;I assume it's the reason why i stillm got those messages :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AntoineDRN_1-1651759224743.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19448iEF3F5804A9FAE43D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AntoineDRN_1-1651759224743.png" alt="AntoineDRN_1-1651759224743.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AntoineDRN_2-1651759251090.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19449iDF0BEE7BBDFC9170/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AntoineDRN_2-1651759251090.png" alt="AntoineDRN_2-1651759251090.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AntoineDRN_3-1651759267747.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19450i9FE873AF6739A2EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AntoineDRN_3-1651759267747.png" alt="AntoineDRN_3-1651759267747.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please let me know if I did something wrong or if i missed something,&lt;/P&gt;&lt;P&gt;Thanks in advance for your help!&lt;/P&gt;&lt;P&gt;Regards ,&lt;/P&gt;&lt;P&gt;Antoine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 14:04:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Indexing-problems/m-p/596528#M11517</guid>
      <dc:creator>AntoineDRN</dc:creator>
      <dc:date>2022-05-05T14:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Indexing problems</title>
      <link>https://community.splunk.com/t5/Installation/Indexing-problems/m-p/596532#M11518</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/245432"&gt;@AntoineDRN&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to set the $SPLUNK_DB variable on Indexers in &lt;STRONG&gt;$SPLUNK_HOME/etc/splunk-launch.conf&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;you should find it commented, you have to uncomment it and use the correct folder where indexes are located,&lt;/P&gt;&lt;P&gt;by default it's &lt;STRONG&gt;$SPLUNK_HOME/var/lib/splunk&lt;/STRONG&gt;, in your case it should be &lt;STRONG&gt;/dev/vda1&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Then, you have to insert in each path that you find in each indexes,conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[index_name]
coldPath = $SPLUNK_DB\index_name\colddb
homePath = $SPLUNK_DB\index_name\db
thawedPath = $SPLUNK_DB\index_name\thaweddb&lt;/LI-CODE&gt;&lt;P&gt;Remember to restart Splunk after conf files upgrade.&lt;/P&gt;&lt;P&gt;In this way the indexes.conf files address the correct folders.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 05 May 2022 14:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Indexing-problems/m-p/596532#M11518</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-05T14:25:44Z</dc:date>
    </item>
  </channel>
</rss>

