Splunk Dev

Archiving frozen data to network drive

sudhir7
Explorer

I am trying to archive data to the network drive, I have following stanza in my indexes.conf file.

[indexName]
frozenTimePeriodInSecs = 31622400
coldToFrozenDir = \\netwotkDrive\splunk\indexName\frozendb

This setting is not working for me.
Has anyone else faced a similar situation? Are there any configurational settings I am missing?

suamme1
Engager

I wasn't able to get this to work directly to a network folder as you posted. If you are still working on it, I ended up configuring a folder on each indexer that is a NTFS junction to a remote file share. This way, the splunk service writes as if it is a local file and NTFS takes care of the rest. I'm not sure if it's a supported solution, but my low-volume cluster has been running like this for several years with no apparent issues.

One thing to note with an indexer cluster is to point the junction to a different folder within the share for each machine to avoid naming collisions (IndexerA's junction should point to \server\share\indexerA and IndexerB's to \server\share\indexerB or some similar scheme).

0 Karma

dkeck
Influencer

Hi,

did you restart after changing this?

0 Karma

sudhir7
Explorer

@dkeck Yes.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...