Getting Data In

Storing the SPLUNK logs on hard disks (different from C partition)

twieczorkowski
Explorer

Hi,

I'v just installed the physical server and the SPLUNK application.
Windows Server 2008 R2 (x64 - SPLUNK).
On this server there is a RAID 5 and 2 partitions C (80GB) and D (500GB).

The system and the SPLUNK is installed on the "C" drive.

I'would like to store much more data than 80GB. So the system partition is not enough.
I wold like to store the SPLUNK data (logs etc) on D partition.

Is there such a possibility or I will have to reinstall this server and create one big partition for system and SPLUNK?

BR,
Tom

Tags (2)
0 Karma

alberttra
Engager

Hi, i can see the path index, but i can not change it? Can you think of any reason?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@alberttra This question is almost 7 years old so you're unlikely to get many responses. You should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

nelsonb
Explorer

You can designate the location of the indexes under "Manager» System settings» General settings". From there scroll down to Index Settings and designate the new Path to indexes. You should be able to point it to your second partition there.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...