I created a new F: drive for my archiving or Frozen path. Currently everything is configured to the default and filling up my C: drive. How do I configure my indexes.conf to have my coldtofrozenpath to be on the F: drive?
Hi dbatts,
you can put indexes.conf in one app (custom or default) or in $SPLUNK_HOME/etc/system/local (but I don't like!).
I usually put each of them in the related App.
So You can insert in your indexes.conf a stanza like this:
[my_index]
homePath = C:\splunk_data\my_index\db
coldPath = F:\splunk_data\my_index\colddb
thawedPath = F:\splunk_data\my_index\thaweddb
don't use spaces in path.
For other information see https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Indexesconf
Bye.
Giuseppe
P.S.:
I usually use Windows only for test, never for production environments!
Hi dbatts,
you can put indexes.conf in one app (custom or default) or in $SPLUNK_HOME/etc/system/local (but I don't like!).
I usually put each of them in the related App.
So You can insert in your indexes.conf a stanza like this:
[my_index]
homePath = C:\splunk_data\my_index\db
coldPath = F:\splunk_data\my_index\colddb
thawedPath = F:\splunk_data\my_index\thaweddb
don't use spaces in path.
For other information see https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Indexesconf
Bye.
Giuseppe
P.S.:
I usually use Windows only for test, never for production environments!
In indexes.conf for your given index you should set:
coldToFrozenDir = f:\Splunk\data\yourindexName
You need to set this to a path (not just a drive letter) and you may want to specify your index name to help keep things tidy.
See: https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Indexesconf#PER_INDEX_OPTIONS