Getting Data In

Indexer almost out of storage space

kmcconnell
Path Finder

I'm about to run out of room on one of our indexers. We have two indexers setup and we are doing distributed indexing. I had an additional 2TB drive added to the one indexer, but I’m wondering if we need to add an additional drive to the other indexer. My plan was to modify the indexes.conf and start sending the two largest indexes cold storage to the new drive (like below). I assume I would copy the “index_to_change\colddb” folder structure to the new drive also. If I’m missing something or going about this wrong, please let me know. I’m pretty new at Splunk and I’m still learning.

[volume:primary]
path = D:\splunkdata
maxVolumeDataSizeMB = 1990000

[volume:cold]
path = E:\splunkdata
maxVolumeDataSizeMB = 1990000

[index_to_change]
homePath = volume:primary/defaultdb/db
coldPath = volume:cold/defaultdb/colddb

Tags (1)
0 Karma
1 Solution

_d_
Splunk Employee
Splunk Employee

That should work but it is advisable that all indexers (2 in your case) are configured identically.

View solution in original post

0 Karma

_d_
Splunk Employee
Splunk Employee

That should work but it is advisable that all indexers (2 in your case) are configured identically.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...