Splunk Search

Linux Indexer root partition 100% full

johnklaiber
New Member

I had a previous case open on this (#1591420) but cannot seem to find it anymore.

In there Joe Love validated my idea to implement a move of our Splunk DB to a much larger partition and update Splunk config.

The referenced solution was the "easiest method' in this support case:
https://answers.splunk.com/answers/210748/splunk-amazon-ami-is-using-the-root-partition-to-s.html

As I was looking to implement this "easiest method" solution, for some reason our latest version of Splunk does not have the "/opt/splunk/splunk-launcher.cfg" file. We are version 7.3.0, has something changed since this original posting?

In fact, the .cfg files I see are in /etc and most are log- files. Is there a new file for updating the SPLUNK_DB= value?

Tags (1)
0 Karma

soumyasaha25
Contributor

as per this doc the splunk-launch.conf file should be in "$SPLUNK_HOME/etc/ " directory.

if you want to change the location of SPLUNK_DB change it in splunk-launch.conf

NOTE:
This conf file is different from most splunk conf files. There is only one in the whole system, located at $SPLUNK_HOME/etc/splunk-launch.conf; further, there are no stanzas, explicit or implicit. Finally, any splunk-launch.conf files in etc/apps/... or etc/users/... will be ignored.

0 Karma

johnklaiber
New Member

Thank you. I did locate it and was able to restore functionality of the indexer.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...