Getting Data In

Storing the SPLUNK logs on hard disks (different from C partition)

twieczorkowski
Explorer

Hi,

I'v just installed the physical server and the SPLUNK application.
Windows Server 2008 R2 (x64 - SPLUNK).
On this server there is a RAID 5 and 2 partitions C (80GB) and D (500GB).

The system and the SPLUNK is installed on the "C" drive.

I'would like to store much more data than 80GB. So the system partition is not enough.
I wold like to store the SPLUNK data (logs etc) on D partition.

Is there such a possibility or I will have to reinstall this server and create one big partition for system and SPLUNK?

BR,
Tom

Tags (2)
0 Karma

alberttra
Engager

Hi, i can see the path index, but i can not change it? Can you think of any reason?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@alberttra This question is almost 7 years old so you're unlikely to get many responses. You should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

nelsonb
Explorer

You can designate the location of the indexes under "Manager» System settings» General settings". From there scroll down to Index Settings and designate the new Path to indexes. You should be able to point it to your second partition there.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...