Knowledge Management

Can the _introspection index use SmartStore?

esalesapns2
Communicator

I created a fresh index cluster in AWS using the Splunk AMI, upgraded to 7.2.5.1.

In the "Configure SmartStore" doc, Splunk says, "The following indexes.conf settings must remain unset: bloomHomePath sumaryHomePath tstatsHomePath."

To try to enforce this on all indexes, in my master node, I created indexes.conf in etc/master-apps/_cluster/local and put in:

bloomHomePath =
summaryHomePath =
tstatsHomePath =

When I run "splunk validate cluster-bundle" I don't get an error, but when I then run "splunk show cluster-bundle-status" it says,

[Critical] stanza=_introspection Required parameter=tstatsHomePath not configured

Unless I remove the tstatsHomePath setting, the bundle won't validate.

dm1
Contributor

were you able to fix this ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
In this context unsetting means that you shouldn't put anything in those and you must use defaults here. In previous examples you just unset those, which is different thing than use default. You cannot set any value (including unset) in your indexes.conf. Just remove those definitions from it and use what ever comes from system/default/indexes.conf.
r. Ismo
0 Karma

dm1
Contributor

If you refer to this page https://docs.splunk.com/Documentation/Splunk/8.2.4/Indexer/ConfigureSmartStore#Settings_in_indexes.c...

there are settings which are "must remain unset" and settings that "must retain their default values", but as per your comment, both should mean the same, isnt it ?

if keeping them unset is keeping them as default, why would Splunk doc put these settings in differently ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
My understanding is that those means same, but I suggest that you ask that on those docs pages. Splunk usually answers and clarify those quite soon.
0 Karma

dm1
Contributor

I have asked them still waiting on for response.

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...