Getting Data In

Setting the homePath option in indexes.conf on Windows?

maverick
Splunk Employee
Splunk Employee

On Windows, I want to set the homePath in my indexes.conf file for a new index I created, which is located on my E:\ drive.

The online Splunk guides have examples that use

homePath = $SPLUNK_HOME/blah/....

but there are no examples of how an actual path on Windows would be specified.

I have the following setting in my indexes.conf, which does not seem to work.

[myIndex]
homePath = e:\Splunk_Indexes\myIndex\

Assuming my format is incorrect, what is the path supposed to look like so that Splunk used my E:\ drive?

0 Karma

treinke
Builder

This is what I did. I have higher speed drives for the data coming in and then the cold data gets moved to a lower speed / high capacity drive.

Make a copy of c:\program files\splunk\etc\system\default\indexes.conf and place it in c:\program files\splunk\etc\system\local\

Change the $SPLUNK_DB of the index you want to move.

Example:

[myindex]
homePath   = E:\SplunkIndexes-warm\myindex\db
coldPath   = F:\SplunkIndexes-cold\myindex\colddb
thawedPath = F:\SplunkIndexes-thawed\myindex\thaweddb
maxMemMB = 20
maxConcurrentOptimizes = 6
maxHotIdleSecs = 86400
maxHotBuckets = 10
maxDataSize = auto_high_volume

Once you save the file, restart Splunk and it will move the effected indexes to the new folder/drives.

There are no answer without questions
0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...