- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it possible to change dump folder on a windows splunk ent. instance?
Hello all,
how is possible to change default dump folder on Windows?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @linspec9721,
as @Azeemering asked, what do you mean with "dump folder"?
Anyway, on Splunk you can modify the installation folder (called $SPLUNK_HOME) and the folder containing the indexes (called $SPLUNK_DB).
The folder containing temporary files ($SPLUNK_HOME/var/run) isn't changeable.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Azeemering @gcusello,
I mean the crash dump folder.
Is it possibile to change the /var/log/splunk folder path?
I am on 9.0.0.
Thank you
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @linspec9721,
for my knowldege, the only changeable folders are the installation folder (called $SPLUNK_HOME) and the folder containing the indexes (called $SPLUNK_DB), not others.
Why do you want to change it?
in this way, crash logs are indexed by Splunk and you maintain them.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
sometimes it happens that crash dumps fill up the partion of $SPLUNK_HOME and we need to manually clean it.
Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @linspec9721,
this means that you have a very narrow filesystem, maybe it could be a good idea giving a little more space to your file system.
Anyway, I suppose that it isn't so frequent a crash of your system, so deleting crash log files isn't a so frequent job.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

What do you mean? I don't understand your question.
Please read this:
https://docs.splunk.com/Documentation/SplunkCloud/8.2.2203/SearchReference/Dump
