Archive

Linux Indexer root partition 100% full

New Member

I had a previous case open on this (#1591420) but cannot seem to find it anymore.

In there Joe Love validated my idea to implement a move of our Splunk DB to a much larger partition and update Splunk config.

The referenced solution was the "easiest method' in this support case:
https://answers.splunk.com/answers/210748/splunk-amazon-ami-is-using-the-root-partition-to-s.html

As I was looking to implement this "easiest method" solution, for some reason our latest version of Splunk does not have the "/opt/splunk/splunk-launcher.cfg" file. We are version 7.3.0, has something changed since this original posting?

In fact, the .cfg files I see are in /etc and most are log- files. Is there a new file for updating the SPLUNK_DB= value?

Tags (1)
0 Karma

Contributor

as per this doc the splunk-launch.conf file should be in "$SPLUNK_HOME/etc/ " directory.

if you want to change the location of SPLUNK_DB change it in splunk-launch.conf

NOTE:
This conf file is different from most splunk conf files. There is only one in the whole system, located at $SPLUNK_HOME/etc/splunk-launch.conf; further, there are no stanzas, explicit or implicit. Finally, any splunk-launch.conf files in etc/apps/... or etc/users/... will be ignored.

0 Karma

New Member

Thank you. I did locate it and was able to restore functionality of the indexer.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!