Getting Data In

Syntax when creating volumes

thoree
Explorer

Hi,

I am trying to create my first Splunk-volume and to set an index to point to this volume. But when I try to start Splunk I get the error-message shown below. My config is shown below the error. Can somebody tell what is wrong in my config? What I want is to define a volume pointing to the directory above the directory for the indexes and then use this volume for all indexes.

Error-message:

Problem parsing indexes.conf: Index stanza 'os' refers to non-existent volume 'v
olume:splunkdata/os/db'
Validating databases (splunkd validatedb) failed with code '1'.  Please file a c
ase online at http://www.splunk.com/page/submit_issue

My config in indexes.conf:

# Volume for lagring av Splunk-data 03.05.2012 (TEE)

[volume:splunkdata]
path = d:/Program Files/Splunk/var/lib/splunk
maxVolumeDataSizeMB = 350000

[os]
homePath = volume:splunkdata/os/db
coldPath = volume:splunkdata/os/colddb
thawedPath = $SPLUNK_DB/os/thaweddb
Tags (1)
0 Karma
1 Solution

thoree
Explorer

The problem was that I used wrong "slashes".

View solution in original post

0 Karma

thoree
Explorer

The problem was that I used wrong "slashes".

0 Karma

Drainy
Champion

Shouldn't the path be (I may be wrong);

path = d:\Program Files\Splunk\var\lib\splunk

Also, have a look at http://docs.splunk.com/Documentation/Splunk/latest/admin/indexesconf

You need a define a volume per hot, cold etc. The directory structure is included within the volume definition so your index definition would instead be;

[os]
homePath = volume:splunkdatahot/os
coldPath = volume:splunkdatacold/os
thawedPath = $SPLUNK_DB/os/thaweddb

Drainy
Champion

Awesome. Feel free to click the tick under the arrows on the left to accept just to help others in future 🙂

0 Karma

thoree
Explorer

Thanks for your answer. The problem was that I used the wrong "slashes", should be \ instead of /.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...