Getting Data In

Change SPLUNK_HOME after install on Windows?

MattK
Explorer

Have a 4.1.4 install on Windows 2008 R2 that I would like to improve performance on. Indexes stored on dedicated RAID-5 volume after setting path in splunk-launch.conf.

I see disk activity on the system OS RAID-1 volume (C:\Program Files\Splunk\var) that I would like to move to a different RAID-5 volume from the indexes.

Can this be performed without a reinstall? Changing SPLUNK_HOME in splunk-launch.conf seemed to prevent the splunkd process from starting.

Tags (2)
0 Karma
1 Solution

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

View solution in original post

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

MattK
Explorer

Reinstall is the approach I took to reset SPLUNK_HOME.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...