Getting Data In

How on earth do I edit indexes.conf


indexes.conf is set to read only

I can't even change my frozenbucket retention period

Tags (1)
0 Karma

If you are on the indexer, check the path /opt/splunk/etc/system/local/indexes.conf

0 Karma


so where do I edit indexes.conf?

0 Karma


Are you attempting to edit the file in the default directory? If so, you should be overriding the entries in default with a file in the local directory. See the docs for more info.


Make it writeable?

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!