Installation

What shuold I do? I can not give more space to /

christianubeda
Path Finder

Hi team!

I installed my splunk in default path /opt/splunk...

But I only have 20 GB in / and 500GB free space in /home

What shuold I do? I can not give more space to /

Shuold I move my indexers to /home?

Help please...

Thank you!

Tags (1)
0 Karma

nickhills
Ultra Champion

If you have a volume with space available you could mount that 'over the top' or 'within' your Splunk filesystem.

In deployments I have worked on, it's common to do both!

For indexers in particular, there is performance optimization by using different classes of storage volume for different bucket types.
You might therefore have a separate volume mounted as /opt/splunk, and different volumes also mounted in /opt/splunk/var/li b/splunk/[hot|cold|frozen]/

If you have a volume to use for this, the safest way is to stop Splunk, rsync the contents of your old /opt/splunk to your new volume, then mount the new volume over the top of /opt/splunk and start Splunk to test.

If my comment helps, please give it a thumbs up!
0 Karma

lakshman239
Influencer

you can create/update SPLUNK_DB=/home/splunk_data in /opt/splunk/etc/splunk-launch.conf and restart splunk. Also, in all your indexes.conf, ensure this SPLUNK_DB is used.

This will create all new indexes in that path.

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...