Getting Data In

How on earth do I edit indexes.conf

Explorer

indexes.conf is set to read only

I can't even change my frozenbucket retention period

Tags (1)
0 Karma

If you are on the indexer, check the path /opt/splunk/etc/system/local/indexes.conf

0 Karma

Explorer

so where do I edit indexes.conf?

0 Karma

Champion

Are you attempting to edit the file in the default directory? If so, you should be overriding the entries in default with a file in the local directory. See the docs for more info.

Legend

Make it writeable?

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!