Getting Data In

splunk index

kowsikreddy
Loves-to-Learn

Hi

We are on migration on 2 different environments for windows OS.

Can we get details, where we have define new indexes in the indexer server?

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kowsikreddy,

you can see the location of each index in [Settings -- Indexes] - Home Path.

If you have $SPLUNK_DB, by default it's:

$SPLUNK_HOME\var\lib\splunk

otherwise it's defined in the conf file

$SPLUNK_HOME\etc\splunk-launch.conf

 Ciao.

Giuseppe

0 Karma

brent_weaver
Builder

It is possible that these indexes are defined outside the $SPLUNK_HOME so you may want to write a little power shell script to find the indexes.conf file to see where things are defined. I have fully qualified paths in my indexes.conf file.

 

if it is an index cluster they would need to be configured in master apps directory on the cluster master server 

 

0 Karma
Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...