Getting Data In

Is thawedPath in indexes.conf recommended?

sympatiko
Communicator

Hi Splunkers,

I just want to ask if it is required in indexes.conf to specify the thawedPath?

Thanks,
Eddel

Tags (2)
0 Karma
1 Solution

Sourabhv05
Communicator

yes its mandatory.

View solution in original post

0 Karma

Sourabhv05
Communicator

yes its mandatory.

0 Karma

sympatiko
Communicator

Thank u bro!

Can you give some explanation. Explanation based on experience not just giving the splunk doc links 😃 .

0 Karma

ppablo
Retired

Hi @sympatiko

I tried searching through all Splunk Answers and couldn't find a detailed explanation for this. I know you didn't want to just hear something from the documentation, but it does explicitly say "Required. Splunk will not start if an index lacks a valid thawedPath." So it doesn't seem like there's any ifs ands or buts with this setting. If I hear a more in depth explanation as to why it's required, I'll post an update here.

0 Karma

sympatiko
Communicator

Thanks for the info bro! I'm still exploring splunk. Have a great day!

0 Karma

lmyrefelt
Builder

set it and forget it 😉

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...