Getting Data In

How to change modinputs checkpoints location

MIJ75
Explorer

Hi,

We are looking to change the location of the modinputs checkpoints.
By default, the checkpoints are in $SPLUNK_HOME/var/lib/splunk/modinputs/
I did not find any parameter to change this.
Do you know if/how we can do this?

FYI, the needs comes from our citrix servers, they start on a golden image, but have their eventlogs in a persistent location (D drive). So each time the sever reboot, we loose the checkpoints and all the events in the eventlogs are forwarded, so we have duplicate events in splunk. We'd like to define the location of the checkpoints to the persistent location.

If not possible we'll have to use the current_only parameter in the input, but we'll lose some startup event and we'd like to avoid this.

Thanks
Michael

jconger
Splunk Employee
Splunk Employee

I haven't tested this, but a symbolic link may work. Link either the entire modinputs folder, or individual subfolders to a folder on your 😧 drive. This would require a change on your PVS or MCS golden image though.

MIJ75
Explorer

Yes, we thought about this option. Not tested yet. I'll check with the citrix admin.
But I would check if we can change this default path with a config file or something before doing this.

Thanks for your input.

0 Karma

MIJ75
Explorer

Just to let you know. We have tested the symbolic links and all is working as expected.
Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...