Deployment Architecture

Where is actually SPLUNK_DB located?

pavanae
Builder

Hi,

Whenever i create a new index in my licensed standalone version it automatically taking the home path,cold path as follows

$SPLUNK_DB/hot/index1/db
$SPLUNK_DB/cold/index1/db

Where can i see the cold and hot bucket logs?

1 Solution

MuS
Legend

Hi pavanae,

again docs to the rescue; it is set in splunk-launch.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Splunk-launchconf

cheers, MuS

View solution in original post

MuS
Legend

Hi pavanae,

again docs to the rescue; it is set in splunk-launch.conf http://docs.splunk.com/Documentation/Splunk/latest/Admin/Splunk-launchconf

cheers, MuS

pavanae
Builder

Just a small Clarification so SPLUNK_DB is actually the path in the splunk server or some outside path?

0 Karma

J0hnWebster
New Member

Which server is splunk-launch.conf found on?
It would be helpful to note on ALL questions regarding file locations, which functional node they're on.
Thanks.

0 Karma

MuS
Legend

This file is used on all Splunk instances, even universal forwarders, and is found in $SPLUNK_HOME/etc on *nix or $SPLUNK_HOME/etc on *win

cheers, MuS

0 Karma

samhodgson
Path Finder

What if you have a distributed environment? your indexes are not stored on the local filesystem. Do I need to have $SPLUNK_DB set on my searchhead?

0 Karma

nickhills
Ultra Champion

Indexes are always stored on a local filesystem.
Even if that filesystem is mounted from elsewhere, Splunk treats it as local (Don't do this btw!)
Its the same as @MuS mentioned on UFs, HFs, SHs and even distributed indexers.

If my comment helps, please give it a thumbs up!

MuS
Legend

No, $SPLUNK_HOME is the path to Splunk. $SPLUNK_DB is the path to your indexes which can be stored outside of Splunk

pavanae
Builder

Thanks got it

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...