Getting Data In

Change SPLUNK_HOME after install on Windows?

MattK
Explorer

Have a 4.1.4 install on Windows 2008 R2 that I would like to improve performance on. Indexes stored on dedicated RAID-5 volume after setting path in splunk-launch.conf.

I see disk activity on the system OS RAID-1 volume (C:\Program Files\Splunk\var) that I would like to move to a different RAID-5 volume from the indexes.

Can this be performed without a reinstall? Changing SPLUNK_HOME in splunk-launch.conf seemed to prevent the splunkd process from starting.

Tags (2)
0 Karma
1 Solution

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

View solution in original post

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

MattK
Explorer

Reinstall is the approach I took to reset SPLUNK_HOME.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...