Getting Data In

Unable to add CIFS share as frozen path

matchpump
New Member

I'm trying to create a new index and specify a CIFS share as "Frozen Path". But I got an error "Unable to load index configuration: In index 'index1': Failed to create directory '\192.168.110.140\archive\index1\' (指定されたパスは無効です。)
"指定されたパスは無効です。" is translated into "specified path is invalid"(This message seems generated from Windows OS because the locale setting of splunk is english on Japanese Windows OS).
I can access the path above from explorer, so I believe it's not a access privilege problem.
I also tested to add drive letter for the path( \192.168.110.140\archive\index1\ -> Y:).
This work fine. But I can't set the path to Y:xxx. I got the same error as above.

Any advise or thoughts is welcome!

Thanks.

0 Karma

schose
Builder

if Splunk is running as system user the share and filesystem have to be writeable for the account "domain\computername$".

For troubleshooting select a useraccount which is local admin and let splunk run in this account. Try to create a file with this account.

Otherwise use psexec -s from sysinternals to test Share and filesystem right as system user.

Regards,

Andreas

0 Karma

jkat54
SplunkTrust
SplunkTrust

Shouldn't it be y:\ ?

Are you testing as the same user that splunk runs as?

0 Karma

matchpump
New Member

Yes, y: is just a typo.
Splunk is running as administrator as same as the testing user.

The number of the index will be much more than the number of alphabets.
So the frozen path is needed to be subdirectory of a drive letter.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...