Deployment Architecture

SplunkForwarder installation disk availability

tom1981
Engager

Hello,

We're planning a capacity adjustment activity (resize of C: drives).
Our SplunkForwarders are installed on the C: drives.
If the disk were to become unavailable for a period of time, does this affect the SplunkForwarder in any way? Any action needs to be taken after the disk is available again (service recycle etc.)?
Thanks a bunch!

Have a great day.

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Stop the forwarder while you're working on the drive. As long as files are not moved, it will resume where it left off once you start the forwarder.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Stop the forwarder while you're working on the drive. As long as files are not moved, it will resume where it left off once you start the forwarder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

tom1981
Engager

Got it.
What is the possible negative impact to the Forwarder if this is not done?

Thanks a lot.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the forwarder cannot access the drive at the very least it will throw endless errors into the logs about it. If the log is on the same drive then there's no telling what it will do. Also, if there is a critical file it cannot access then expect the forwarder to crash. Better to just shut it down.

---
If this reply helps you, Karma would be appreciated.

tom1981
Engager

Perfect. Will do.
Thanks a lot, Rich, for the fast reply and all the info.

Have a great day.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...