Installation

Unable to send data to a remote on-network server or UNC path

rewritex
Contributor

I want to send indexed data to another server but I'm running into an error of unable to create/find path.
Q: Is this a permissions issue?
Q: Maybe this is a syntax error?
….. Any advice would be helpful. Thank you!

Info:
- Windows 2016 environment
- I have two servers setup with UNC paths of \\server01\hotwarmstorage and \\server02\coldstorage that use a service account credential (ie svcSplunk) to gain access.
- Splunk is installed using the SYSTEM account.
- I've tried to use the UNC path and also mapped the storage drives to Y: and Z: on the indexers and master
- While on the indexer and in CMD I can do y: to access the network path


Errors:
1) Failed to create directory 'Y:\hotwarmstorage\index-test\db' (The system cannot find the path specified.);
2) \\server01\hotwarmstorage\index-test\db' (The specified path is invalid)
3) I've tried a non-credentialed network path  \\server03\splunkstorage and I get an error '\\server03\splunkstorage\index-test\db' (Cannot create a file when that file already exists.);

Master indexes.conf attempts
Attempt 1):
[volume:seam_test_hotwarm]
path = Y:\hotwarmstorage

Attempt 2):
[volume:seam_test_hotwarm]
path = \\server01\hotwarmstorage


Index -  indexes.conf:
[index-test]
repFactor = 0
homePath = volume:seam_test_hotwarm/index-test/db

 

Labels (3)
Tags (2)
0 Karma

Richfez
SplunkTrust
SplunkTrust

I hate to say it, but I think that's simply not supported.

https://docs.splunk.com/Documentation/Splunk/8.0.6/Installation/Systemrequirements#Considerations_re...

To wit -

Only use CIFS/SMB shares for cold or frozen data (no hot or warm), and Splunk will *disable* any index it encounters with a non-physical drive letter.

Sorry!  Even if this answer isn't the one you were hoping for, if it helps you can mark it accepted (feel free to sigh heavily at that time) and click the button to give a karma point for it).

-Rich

 

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...