Installation

What shuold I do? I can not give more space to /

christianubeda
Path Finder

Hi team!

I installed my splunk in default path /opt/splunk...

But I only have 20 GB in / and 500GB free space in /home

What shuold I do? I can not give more space to /

Shuold I move my indexers to /home?

Help please...

Thank you!

Tags (1)
0 Karma

nickhills
Ultra Champion

If you have a volume with space available you could mount that 'over the top' or 'within' your Splunk filesystem.

In deployments I have worked on, it's common to do both!

For indexers in particular, there is performance optimization by using different classes of storage volume for different bucket types.
You might therefore have a separate volume mounted as /opt/splunk, and different volumes also mounted in /opt/splunk/var/li b/splunk/[hot|cold|frozen]/

If you have a volume to use for this, the safest way is to stop Splunk, rsync the contents of your old /opt/splunk to your new volume, then mount the new volume over the top of /opt/splunk and start Splunk to test.

If my comment helps, please give it a thumbs up!
0 Karma

lakshman239
Influencer

you can create/update SPLUNK_DB=/home/splunk_data in /opt/splunk/etc/splunk-launch.conf and restart splunk. Also, in all your indexes.conf, ensure this SPLUNK_DB is used.

This will create all new indexes in that path.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...