Getting Data In

Unable to add CIFS share as frozen path

matchpump
New Member

I'm trying to create a new index and specify a CIFS share as "Frozen Path". But I got an error "Unable to load index configuration: In index 'index1': Failed to create directory '\192.168.110.140\archive\index1\' (指定されたパスは無効です。)
"指定されたパスは無効です。" is translated into "specified path is invalid"(This message seems generated from Windows OS because the locale setting of splunk is english on Japanese Windows OS).
I can access the path above from explorer, so I believe it's not a access privilege problem.
I also tested to add drive letter for the path( \192.168.110.140\archive\index1\ -> Y:).
This work fine. But I can't set the path to Y:xxx. I got the same error as above.

Any advise or thoughts is welcome!

Thanks.

0 Karma

schose
Builder

if Splunk is running as system user the share and filesystem have to be writeable for the account "domain\computername$".

For troubleshooting select a useraccount which is local admin and let splunk run in this account. Try to create a file with this account.

Otherwise use psexec -s from sysinternals to test Share and filesystem right as system user.

Regards,

Andreas

0 Karma

jkat54
SplunkTrust
SplunkTrust

Shouldn't it be y:\ ?

Are you testing as the same user that splunk runs as?

0 Karma

matchpump
New Member

Yes, y: is just a typo.
Splunk is running as administrator as same as the testing user.

The number of the index will be much more than the number of alphabets.
So the frozen path is needed to be subdirectory of a drive letter.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...