Getting Data In

Storing the SPLUNK logs on hard disks (different from C partition)

twieczorkowski
Explorer

Hi,

I'v just installed the physical server and the SPLUNK application.
Windows Server 2008 R2 (x64 - SPLUNK).
On this server there is a RAID 5 and 2 partitions C (80GB) and D (500GB).

The system and the SPLUNK is installed on the "C" drive.

I'would like to store much more data than 80GB. So the system partition is not enough.
I wold like to store the SPLUNK data (logs etc) on D partition.

Is there such a possibility or I will have to reinstall this server and create one big partition for system and SPLUNK?

BR,
Tom

Tags (2)
0 Karma

alberttra
Engager

Hi, i can see the path index, but i can not change it? Can you think of any reason?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@alberttra This question is almost 7 years old so you're unlikely to get many responses. You should post a new question.

---
If this reply helps you, Karma would be appreciated.
0 Karma

nelsonb
Explorer

You can designate the location of the indexes under "Manager» System settings» General settings". From there scroll down to Index Settings and designate the new Path to indexes. You should be able to point it to your second partition there.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...