Installation

Unable to send data to a remote on-network server or UNC path

rewritex
Contributor

I want to send indexed data to another server but I'm running into an error of unable to create/find path.
Q: Is this a permissions issue?
Q: Maybe this is a syntax error?
….. Any advice would be helpful. Thank you!

Info:
- Windows 2016 environment
- I have two servers setup with UNC paths of \\server01\hotwarmstorage and \\server02\coldstorage that use a service account credential (ie svcSplunk) to gain access.
- Splunk is installed using the SYSTEM account.
- I've tried to use the UNC path and also mapped the storage drives to Y: and Z: on the indexers and master
- While on the indexer and in CMD I can do y: to access the network path


Errors:
1) Failed to create directory 'Y:\hotwarmstorage\index-test\db' (The system cannot find the path specified.);
2) \\server01\hotwarmstorage\index-test\db' (The specified path is invalid)
3) I've tried a non-credentialed network path  \\server03\splunkstorage and I get an error '\\server03\splunkstorage\index-test\db' (Cannot create a file when that file already exists.);

Master indexes.conf attempts
Attempt 1):
[volume:seam_test_hotwarm]
path = Y:\hotwarmstorage

Attempt 2):
[volume:seam_test_hotwarm]
path = \\server01\hotwarmstorage


Index -  indexes.conf:
[index-test]
repFactor = 0
homePath = volume:seam_test_hotwarm/index-test/db

 

Labels (3)
Tags (2)
0 Karma

Richfez
SplunkTrust
SplunkTrust

I hate to say it, but I think that's simply not supported.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Installation/Systemrequirements#Considerations_re...

To wit -

Only use CIFS/SMB shares for cold or frozen data (no hot or warm), and Splunk will *disable* any index it encounters with a non-physical drive letter.

Sorry!  Even if this answer isn't the one you were hoping for, if it helps you can mark it accepted (feel free to sigh heavily at that time) and click the button to give a karma point for it).

-Rich

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...