Splunk Enterprise

How to Splunk index path change

thkwon
Explorer

Hello 

I want to save hot/warm and cold separately when I make splunk index.

Hot/Warm is stored in /tmp/hotwarm and cold is stored in /tmp/cold path.

However, it is time to create an index in the Splunk UI.

I know to separate routes from indexes.conf. It's just that I want to save it in the UI as Default in the path I want to save.

What should I do?

Thanks

Labels (1)
0 Karma

manjunathmeti
Champion

hi @thkwon,

You can provide the Home path and Cold path in the UI also.
If you don't provide paths, by default home path is set to $SPLUNK_DB/INDEX_NAME/db and cold path is set to $SPLUNK_DB/INDEX_NAME/colddb.
In the system, $SPLUNK_DB is set to $SPLUNK_HOME/var/lib/splunk.

You can override the new $SPLUNK_DB path/tmp/splunk in $SPLUNK_HOME/etc/splunk-launch.conf file.

SPLUNK_DB = /tmp/splunk

 

If this reply helps you, a like would be appreciated.

Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...