Getting Data In

Unable to move index database to another drive in Windows Server 2019

rahulkumarfgf
Explorer

Hey Guys! I am very new to Splunk Enterprise and it's still in testing phase. I am trying to use this documentation https://docs.splunk.com/Documentation/Splunk/8.0.1/Indexer/MoveAnIndex to move my database to another drive. However, when trying "D:> cacls D:\new\path\for\index /T /E /G :F" command in Windows Server 2019 cmd, I get an error saying "The system cannot find the file specified". I am not sure why does it say that. I have created the new folder in D:\ drive and using the correct path. Any help would be much appreciated.

Thank You!

0 Karma
1 Solution

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @rahulkumarfgf,

Unfortunately I don't have a VM around to test, but I'm guessing that Microsoft finally removed cacls.exe from Windows Server as of 2019. Therefore you'll need to use the icacls.exe command instead. E.g.:
icacls D:\new\path\for\index /t /c /grant "<the user Splunk Enterprise runs as>:(OI)(CI)(F)"

Cheers,

- Jo.

View solution in original post

0 Karma

jhornsby_splunk
Splunk Employee
Splunk Employee

Hi @rahulkumarfgf,

Unfortunately I don't have a VM around to test, but I'm guessing that Microsoft finally removed cacls.exe from Windows Server as of 2019. Therefore you'll need to use the icacls.exe command instead. E.g.:
icacls D:\new\path\for\index /t /c /grant "<the user Splunk Enterprise runs as>:(OI)(CI)(F)"

Cheers,

- Jo.

0 Karma

rahulkumarfgf
Explorer

Thanks! I did try "icacls" but got the same error. I gave permission to the user from "Properties" Section and as of now, I was able to copy the index database. I created a new index and that shows up in the new drive as well. Hopefully, it works. Will update if anything changes.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...