Splunk Enterprise

Can you use a SMB share as cold storage on Splunk for Windows?

fred900
New Member

I have a customer that wants to use Splunk for windows and with the UNIX version I just map the cold storage with the fstab file to automatically map the cold storage export. But with Windows I can't find a way to persistently map a share without a user logged in. I have tried net use /persist and New-PSDrive in windows powershell 3.0 with no luck. Is it possible for the Windows version to write to a smb share without a login?

Tags (1)
0 Karma

schose
Builder

Hi,

Well on windows a network drive (CIFS Share) is mounted on a per-user basis (every user will have a seperate X: drive), while mounting on a UNIX is on a "per system" basis.

Technically you need to map the network drive for the user splunk is running with (default: system). BUT this is NOT supported! You'll find supported configuration at http://docs.splunk.com/Documentation/Splunk/7.1.1/Installation/Systemrequirements below "Supported file systems".

Regards,

Andreas

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...