<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best way to increase partition containing Splunk? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420231#M8178</link>
    <description>&lt;P&gt;Check your indexes.conf,&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;if you did customize the path for some indexes or volumes, you can relocate them manually on a per index basis&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt; if you did not redefine the path of the indexes, you could change the main variable SPLUNK_DB to relocate your indexes&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;here is the way for the default location :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Stop Splunk. &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Mount a new storage, create a special folder for Splunk indexes on it (not not use the main folder for convenience, and make it read/write for the user running Splunk)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then move the indexes data from your /opt/splunk/var/lib/splunk to your /newmount/splunkindexes&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then edit the splunk-launch.conf in $SPLUNK_HOME/etc/ and add SPLUNK_DB=/newmount/splunkindexes&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;then start Splunk.&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Another alternate solution to keep some data on /opt is to use the coldPath option in indexes.conf to try to ask Splunk to move some buckets to the cold location, and keep the hot and warm on the original location. (but this is not always the best long term solution)&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 21:34:33 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2020-09-29T21:34:33Z</dc:date>
    <item>
      <title>What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420228#M8175</link>
      <description>&lt;P&gt;Our splunk is running on /opt and free space is running low.&lt;BR /&gt;
My options in adding space are:&lt;BR /&gt;
1. Extend existing partion&lt;BR /&gt;
2. Create new partition and rsync /opt to new /opt&lt;/P&gt;

&lt;P&gt;Which of these 2 is the better way to go?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 21:50:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420228#M8175</guid>
      <dc:creator>mvor</dc:creator>
      <dc:date>2018-10-08T21:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420229#M8176</link>
      <description>&lt;P&gt;If it's just your Splunk installation, I don't see why you should not just extend the current partition, which can usually be done live on-the-fly with no downtime, depending on your OS and configuration.&lt;/P&gt;

&lt;P&gt;If there are indexes in /opt, I would create a new partition for the indexes, rsync them over there, and linking the new path to the old one. But this has to be done carefully.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 22:26:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420229#M8176</guid>
      <dc:creator>rabbidroid</dc:creator>
      <dc:date>2018-10-08T22:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420230#M8177</link>
      <description>&lt;P&gt;The current setup is that both splunk installation and indexes are on one partition (/opt). &lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 22:37:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420230#M8177</guid>
      <dc:creator>mvor</dc:creator>
      <dc:date>2018-10-08T22:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420231#M8178</link>
      <description>&lt;P&gt;Check your indexes.conf,&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;if you did customize the path for some indexes or volumes, you can relocate them manually on a per index basis&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt; if you did not redefine the path of the indexes, you could change the main variable SPLUNK_DB to relocate your indexes&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;here is the way for the default location :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Stop Splunk. &lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Mount a new storage, create a special folder for Splunk indexes on it (not not use the main folder for convenience, and make it read/write for the user running Splunk)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then move the indexes data from your /opt/splunk/var/lib/splunk to your /newmount/splunkindexes&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then edit the splunk-launch.conf in $SPLUNK_HOME/etc/ and add SPLUNK_DB=/newmount/splunkindexes&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;then start Splunk.&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Another alternate solution to keep some data on /opt is to use the coldPath option in indexes.conf to try to ask Splunk to move some buckets to the cold location, and keep the hot and warm on the original location. (but this is not always the best long term solution)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:34:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420231#M8178</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-29T21:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420232#M8179</link>
      <description>&lt;P&gt;That's not the most ideal setup, but if you want to split them up, then the rsync route should be the way to do it, otherwise just increase the current partition.&lt;/P&gt;

&lt;P&gt;I highly recommend having the indexes on a separate physical storage than the OS and /opt.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 22:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420232#M8179</guid>
      <dc:creator>rabbidroid</dc:creator>
      <dc:date>2018-10-08T22:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420233#M8180</link>
      <description>&lt;P&gt;Okay, I'd better fix this setup now rather than later.&lt;/P&gt;

&lt;P&gt;What would be the watch-outs on implementing this: &lt;BR /&gt;
"create a new partition for the indexes, rsync them over there, and linking the new path to the old one"&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 23:13:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420233#M8180</guid>
      <dc:creator>mvor</dc:creator>
      <dc:date>2018-10-08T23:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420234#M8181</link>
      <description>&lt;P&gt;Make sure permissions are correct on the destination, use &lt;CODE&gt;rsync -auv /old/index/dir/ /new/index/dir&lt;/CODE&gt; to preserve the timestamps, permission and ownership, when done rename the old index directory with the &lt;CODE&gt;mv&lt;/CODE&gt; command, then &lt;CODE&gt;ln -s /new/index/dir /old/index/dir&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Make sure splunk is not running, however you can do an initial rsync while Splunk is up, and when that's sync is done, shut down Splunk, and do the final rsync with the &lt;CODE&gt;--delete&lt;/CODE&gt; flag. this will delete the files that have disappeared from the index while you were doing the initial sync.&lt;/P&gt;

&lt;P&gt;I go for the linking route, because I'm clustered, and I don't want to mess around with indexes.conf by changing the location of the indexes. But if you are not clustered, you can just rename the old folder, create a new folder with the same name, then mount the new partition in the same place the old one was, like this:&lt;BR /&gt;
&lt;CODE&gt;mv /index/folder/location /index/folder/location.OLD&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;mkdir /index/folder/location&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;mount /index/folder/location&lt;/CODE&gt;&lt;BR /&gt;
The last one assuming you put it in fstab.&lt;BR /&gt;
After confirming that everything is in working order, you can delete the old data.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 23:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420234#M8181</guid>
      <dc:creator>rabbidroid</dc:creator>
      <dc:date>2018-10-08T23:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420235#M8182</link>
      <description>&lt;P&gt;Ideally, you should have the splunk Hot/Warm volume on its own partition/disk, different from Cold (also on its own) and different from the install files (also on its own).  You might as well bite the bullet now and fix everything.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Oct 2018 00:24:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420235#M8182</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-10-09T00:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to increase partition containing Splunk?</title>
      <link>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420236#M8183</link>
      <description>&lt;P&gt;thanks!will implement this one.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 00:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/What-is-the-best-way-to-increase-partition-containing-Splunk/m-p/420236#M8183</guid>
      <dc:creator>mvor</dc:creator>
      <dc:date>2018-10-10T00:08:54Z</dc:date>
    </item>
  </channel>
</rss>

