Splunk Enterprise

Can you use a SMB share as cold storage on Splunk for Windows?

fred900
New Member

I have a customer that wants to use Splunk for windows and with the UNIX version I just map the cold storage with the fstab file to automatically map the cold storage export. But with Windows I can't find a way to persistently map a share without a user logged in. I have tried net use /persist and New-PSDrive in windows powershell 3.0 with no luck. Is it possible for the Windows version to write to a smb share without a login?

Tags (1)
0 Karma

schose
Builder

Hi,

Well on windows a network drive (CIFS Share) is mounted on a per-user basis (every user will have a seperate X: drive), while mounting on a UNIX is on a "per system" basis.

Technically you need to map the network drive for the user splunk is running with (default: system). BUT this is NOT supported! You'll find supported configuration at http://docs.splunk.com/Documentation/Splunk/7.1.1/Installation/Systemrequirements below "Supported file systems".

Regards,

Andreas

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...