Getting Data In

Change SPLUNK_HOME after install on Windows?

MattK
Explorer

Have a 4.1.4 install on Windows 2008 R2 that I would like to improve performance on. Indexes stored on dedicated RAID-5 volume after setting path in splunk-launch.conf.

I see disk activity on the system OS RAID-1 volume (C:\Program Files\Splunk\var) that I would like to move to a different RAID-5 volume from the indexes.

Can this be performed without a reinstall? Changing SPLUNK_HOME in splunk-launch.conf seemed to prevent the splunkd process from starting.

Tags (2)
0 Karma
1 Solution

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

View solution in original post

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

MattK
Explorer

Reinstall is the approach I took to reset SPLUNK_HOME.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...