Getting Data In

Syntax when creating volumes

thoree
Explorer

Hi,

I am trying to create my first Splunk-volume and to set an index to point to this volume. But when I try to start Splunk I get the error-message shown below. My config is shown below the error. Can somebody tell what is wrong in my config? What I want is to define a volume pointing to the directory above the directory for the indexes and then use this volume for all indexes.

Error-message:

Problem parsing indexes.conf: Index stanza 'os' refers to non-existent volume 'v
olume:splunkdata/os/db'
Validating databases (splunkd validatedb) failed with code '1'.  Please file a c
ase online at http://www.splunk.com/page/submit_issue

My config in indexes.conf:

# Volume for lagring av Splunk-data 03.05.2012 (TEE)

[volume:splunkdata]
path = d:/Program Files/Splunk/var/lib/splunk
maxVolumeDataSizeMB = 350000

[os]
homePath = volume:splunkdata/os/db
coldPath = volume:splunkdata/os/colddb
thawedPath = $SPLUNK_DB/os/thaweddb
Tags (1)
0 Karma
1 Solution

thoree
Explorer

The problem was that I used wrong "slashes".

View solution in original post

0 Karma

thoree
Explorer

The problem was that I used wrong "slashes".

0 Karma

Drainy
Champion

Shouldn't the path be (I may be wrong);

path = d:\Program Files\Splunk\var\lib\splunk

Also, have a look at http://docs.splunk.com/Documentation/Splunk/latest/admin/indexesconf

You need a define a volume per hot, cold etc. The directory structure is included within the volume definition so your index definition would instead be;

[os]
homePath = volume:splunkdatahot/os
coldPath = volume:splunkdatacold/os
thawedPath = $SPLUNK_DB/os/thaweddb

Drainy
Champion

Awesome. Feel free to click the tick under the arrows on the left to accept just to help others in future 🙂

0 Karma

thoree
Explorer

Thanks for your answer. The problem was that I used the wrong "slashes", should be \ instead of /.

0 Karma
Get Updates on the Splunk Community!

Splunk and Fraud

Watch Now!Watch an insightful webinar where we delve into the innovative approaches to solving fraud using the ...

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...