Getting Data In

Is thawedPath in indexes.conf recommended?

sympatiko
Communicator

Hi Splunkers,

I just want to ask if it is required in indexes.conf to specify the thawedPath?

Thanks,
Eddel

Tags (2)
0 Karma
1 Solution

Sourabhv05
Communicator

yes its mandatory.

View solution in original post

0 Karma

Sourabhv05
Communicator

yes its mandatory.

0 Karma

sympatiko
Communicator

Thank u bro!

Can you give some explanation. Explanation based on experience not just giving the splunk doc links 😃 .

0 Karma

ppablo
Retired

Hi @sympatiko

I tried searching through all Splunk Answers and couldn't find a detailed explanation for this. I know you didn't want to just hear something from the documentation, but it does explicitly say "Required. Splunk will not start if an index lacks a valid thawedPath." So it doesn't seem like there's any ifs ands or buts with this setting. If I hear a more in depth explanation as to why it's required, I'll post an update here.

0 Karma

sympatiko
Communicator

Thanks for the info bro! I'm still exploring splunk. Have a great day!

0 Karma

lmyrefelt
Builder

set it and forget it 😉

0 Karma
Get Updates on the Splunk Community!

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...