Getting Data In

How on earth do I edit indexes.conf


indexes.conf is set to read only

I can't even change my frozenbucket retention period

Tags (1)
0 Karma

If you are on the indexer, check the path /opt/splunk/etc/system/local/indexes.conf

0 Karma


so where do I edit indexes.conf?

0 Karma


Are you attempting to edit the file in the default directory? If so, you should be overriding the entries in default with a file in the local directory. See the docs for more info.


Make it writeable?

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!