Monitoring Splunk

Space Issues In my C-drive

harshavrath
Contributor

Hi,

Splunk is installed in C-drive C:\Program Files\Splunk\var\log\splunk

My Question is can i move the splunk folder(which has occupied 1.04GB) to some otheer drive.

Has anyone come across this issue, I really need your help splunkers.

Any Help is Appreciated,

Thanks.

Tags (3)
0 Karma
1 Solution

dmaislin_splunk
Splunk Employee
Splunk Employee

That would not preserve the data that has already been indexed. You need to read this:

http://docs.splunk.com/Documentation/Splunk/6.0.3/Indexer/Moveanindex#For_Windows_users

View solution in original post

dmaislin_splunk
Splunk Employee
Splunk Employee

That would not preserve the data that has already been indexed. You need to read this:

http://docs.splunk.com/Documentation/Splunk/6.0.3/Indexer/Moveanindex#For_Windows_users

harshavrath
Contributor

Hi David,
According to your link
http://docs.splunk.com/Documentation/Splunk/6.0.3/Indexer/Moveanindex#For_Windows_users
In Step-4 Copying the Indexes to new path
it is given as
copy "C:\Program Files\Splunk\var\lib\splunk\." D:\new\path\for\index /s /e /v /o /k
But in my Splunk Instance the var\\lib has occupied very less space but my var\\log\\splunk has occupied 1.52GB.

0 Karma

harshavrath
Contributor

http://answers.splunk.com/answers/126360/disk-space-error
this is my post after which i changed the path in General Settings

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Try searching more on Splunk Answers as many of these questions have been answered several times already.

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Change your log settings. Read this:

http://docs.splunk.com/Documentation/Splunk/6.0.3/Troubleshooting/WhatSplunklogsaboutitself

For permanent changes, use $SPLUNK_HOME/etc/log.cfg instead.

0 Karma

harshavrath
Contributor

long time ago I have changed the path in System Settings>General Settings under that "Path to indexes=Specified the path"

So from then on all my indexed data is located in the Specified path

So i wanted to know what is the cause for the 1GB of data that is been populated under C:Program Files\Splunk\var\log\splunk

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...