Getting Data In

Syntax when creating volumes

thoree
Explorer

Hi,

I am trying to create my first Splunk-volume and to set an index to point to this volume. But when I try to start Splunk I get the error-message shown below. My config is shown below the error. Can somebody tell what is wrong in my config? What I want is to define a volume pointing to the directory above the directory for the indexes and then use this volume for all indexes.

Error-message:

Problem parsing indexes.conf: Index stanza 'os' refers to non-existent volume 'v
olume:splunkdata/os/db'
Validating databases (splunkd validatedb) failed with code '1'.  Please file a c
ase online at http://www.splunk.com/page/submit_issue

My config in indexes.conf:

# Volume for lagring av Splunk-data 03.05.2012 (TEE)

[volume:splunkdata]
path = d:/Program Files/Splunk/var/lib/splunk
maxVolumeDataSizeMB = 350000

[os]
homePath = volume:splunkdata/os/db
coldPath = volume:splunkdata/os/colddb
thawedPath = $SPLUNK_DB/os/thaweddb
Tags (1)
0 Karma
1 Solution

thoree
Explorer

The problem was that I used wrong "slashes".

View solution in original post

0 Karma

thoree
Explorer

The problem was that I used wrong "slashes".

0 Karma

Drainy
Champion

Shouldn't the path be (I may be wrong);

path = d:\Program Files\Splunk\var\lib\splunk

Also, have a look at http://docs.splunk.com/Documentation/Splunk/latest/admin/indexesconf

You need a define a volume per hot, cold etc. The directory structure is included within the volume definition so your index definition would instead be;

[os]
homePath = volume:splunkdatahot/os
coldPath = volume:splunkdatacold/os
thawedPath = $SPLUNK_DB/os/thaweddb

Drainy
Champion

Awesome. Feel free to click the tick under the arrows on the left to accept just to help others in future 🙂

0 Karma

thoree
Explorer

Thanks for your answer. The problem was that I used the wrong "slashes", should be \ instead of /.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...