I'm attempting to replace the /opt/splunk/var folder with the /var folder via symlink to keep relatively small amount of diskspace for /opt and use a larger amount of space on /var. I've move all of the relevant sub-folders from /opt/splunk/var and then replace the directory with a symlink to /var. When I restart the service, everything is working as I would expect, but I continue to get disk space warnings in the web console.
Is what I'm attempting possible? If so, any suggestions on getting it to work?
Yes it can, for single (serach-head) instances. this will not work multiple search-head instances.
Marc