Splunk Search

Temporary relocating the dispatch folder.

agodoy
Communicator

I am trying to move a massive amount of events from the main index to a dedicated index for the sourcetype. I am trying to do this by running a search and ...|collect index=dedicated index sourcetype=abc.

However, it seems like since the dispatch folder is on my / partition I am running out of space. I would like to temporarily move the folder to the same partitions that hosts the indexes since I have plenty of storage.

Any ideas on how to tackle this one?

Thanks

Tags (1)
0 Karma

agodoy
Communicator

The folder does not have much. I really would suck to do it 1 day at a time for the last 6 months.

Can I rename the main index and then creat another main index or would that mess with Splunk?

0 Karma

yannK
Splunk Employee
Splunk Employee

As long as the index is defined in indexes.conf, you can move and rename it.
So yes.

0 Karma

yannK
Splunk Employee
Splunk Employee

Why not emptying the dispatch folder instead,
Or run your searches over a smaller time range ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...