Getting Data In

How to change modinputs checkpoints location

MIJ75
Explorer

Hi,

We are looking to change the location of the modinputs checkpoints.
By default, the checkpoints are in $SPLUNK_HOME/var/lib/splunk/modinputs/
I did not find any parameter to change this.
Do you know if/how we can do this?

FYI, the needs comes from our citrix servers, they start on a golden image, but have their eventlogs in a persistent location (D drive). So each time the sever reboot, we loose the checkpoints and all the events in the eventlogs are forwarded, so we have duplicate events in splunk. We'd like to define the location of the checkpoints to the persistent location.

If not possible we'll have to use the current_only parameter in the input, but we'll lose some startup event and we'd like to avoid this.

Thanks
Michael

jconger
Splunk Employee
Splunk Employee

I haven't tested this, but a symbolic link may work. Link either the entire modinputs folder, or individual subfolders to a folder on your 😧 drive. This would require a change on your PVS or MCS golden image though.

MIJ75
Explorer

Yes, we thought about this option. Not tested yet. I'll check with the citrix admin.
But I would check if we can change this default path with a config file or something before doing this.

Thanks for your input.

0 Karma

MIJ75
Explorer

Just to let you know. We have tested the symbolic links and all is working as expected.
Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...