Splunk Enterprise

SmartStore local cache migration

hansmaldonado
New Member

How can I migrate SmartStore's local storage to a new storage device with no interruption to search and indexing functionality?
Could it be as simple as updating homePath one index at a time, restarting the indexers, and allowing the cache manager to do the rest? 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @hansmaldonado 

The easiest thing might be to push an update out via the Cluster Manager to point to the new home path, however this will ultimately mean that you have zero cache and subsequent searches may be slow whilst the cache re-populates. 

If you wanted to retain the cached data to prevent this then I think this may be possible, depending on your configuration/architecture. While in maintenance mode, shutdown one indexer at a time, move the cached files from the existing location to the home path and then update the indexes.conf to reflect the new path. Once you start the indexer back up you will have the original cache files locally on that indexer but in the new location. 

You will then need to do this for each indexer. This isnt necessarily the ideal way to do it but will mean that you do not need to re-download cached data. This will also mean that you indexes.conf will vary between indexers until you have completed. Once complete you should push out an updated indexes.conf via the CM with the updated settings so that you arent in a position where it could revert back! 

I would recommend trying this approach in a development environment first to ensure you are happy with the process involved. 

Please let me know how you get on and consider upvoting/karma this answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...