Splunk Search

Linux Indexer root partition 100% full

johnklaiber
New Member

I had a previous case open on this (#1591420) but cannot seem to find it anymore.

In there Joe Love validated my idea to implement a move of our Splunk DB to a much larger partition and update Splunk config.

The referenced solution was the "easiest method' in this support case:
https://answers.splunk.com/answers/210748/splunk-amazon-ami-is-using-the-root-partition-to-s.html

As I was looking to implement this "easiest method" solution, for some reason our latest version of Splunk does not have the "/opt/splunk/splunk-launcher.cfg" file. We are version 7.3.0, has something changed since this original posting?

In fact, the .cfg files I see are in /etc and most are log- files. Is there a new file for updating the SPLUNK_DB= value?

Tags (1)
0 Karma

soumyasaha25
Contributor

as per this doc the splunk-launch.conf file should be in "$SPLUNK_HOME/etc/ " directory.

if you want to change the location of SPLUNK_DB change it in splunk-launch.conf

NOTE:
This conf file is different from most splunk conf files. There is only one in the whole system, located at $SPLUNK_HOME/etc/splunk-launch.conf; further, there are no stanzas, explicit or implicit. Finally, any splunk-launch.conf files in etc/apps/... or etc/users/... will be ignored.

0 Karma

johnklaiber
New Member

Thank you. I did locate it and was able to restore functionality of the indexer.

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...