Deployment Architecture

Can the /opt/splunk/var directory be symlinked to /var?

nbeyer_cerner
New Member

I'm attempting to replace the /opt/splunk/var folder with the /var folder via symlink to keep relatively small amount of diskspace for /opt and use a larger amount of space on /var. I've move all of the relevant sub-folders from /opt/splunk/var and then replace the directory with a symlink to /var. When I restart the service, everything is working as I would expect, but I continue to get disk space warnings in the web console.

Is what I'm attempting possible? If so, any suggestions on getting it to work?

Tags (3)
0 Karma

mkelderm
Path Finder

Yes it can, for single (serach-head) instances. this will not work multiple search-head instances.

Marc

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...