Getting Data In

Change SPLUNK_HOME after install on Windows?

MattK
Explorer

Have a 4.1.4 install on Windows 2008 R2 that I would like to improve performance on. Indexes stored on dedicated RAID-5 volume after setting path in splunk-launch.conf.

I see disk activity on the system OS RAID-1 volume (C:\Program Files\Splunk\var) that I would like to move to a different RAID-5 volume from the indexes.

Can this be performed without a reinstall? Changing SPLUNK_HOME in splunk-launch.conf seemed to prevent the splunkd process from starting.

Tags (2)
0 Karma
1 Solution

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

View solution in original post

southeringtonp
Motivator

Changing $SPLUNK_HOME is best done with a reinstall, but if you just want to move the indexes, it's overkill.

Instead, change $SPLUNK_DB.

Take a look at:
     http://www.splunk.com/base/Documentation/4.1.5/Admin/Moveanindex

It does't mention it in the docs page, but you should also review any indexes.conf files, looking for any hard-coded paths. Most paths should already be relative to $SPLUNK_DB.

MattK
Explorer

Reinstall is the approach I took to reset SPLUNK_HOME.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...