Missing Events after SPLUNK_HOME move

New Member

Hello -

I moved the c:\program files\splunk folder to my 😧 drive for more space. Everything seems to work fine, except I'm missing events from my WinEventLog:Security SourceType. The last event is the moment I stopped the splunk service to move the database. I updated the c:\program files\splunk\etc\splunk-launch.conf to reflect the new location:


Is there something I need to run to rebuild anything or repair permissions?

Thanks in advance -

0 Karma

Splunk Employee
Splunk Employee
  • Please check ps -ef | grep splunkd, make sure there is no dual process running.
  • Please check for splunkd.log with any errors with permissions? or grep with the path which should at-least give you something
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!