Splunk Search

Temporary relocating the dispatch folder.

agodoy
Communicator

I am trying to move a massive amount of events from the main index to a dedicated index for the sourcetype. I am trying to do this by running a search and ...|collect index=dedicated index sourcetype=abc.

However, it seems like since the dispatch folder is on my / partition I am running out of space. I would like to temporarily move the folder to the same partitions that hosts the indexes since I have plenty of storage.

Any ideas on how to tackle this one?

Thanks

Tags (1)
0 Karma

agodoy
Communicator

The folder does not have much. I really would suck to do it 1 day at a time for the last 6 months.

Can I rename the main index and then creat another main index or would that mess with Splunk?

0 Karma

yannK
Splunk Employee
Splunk Employee

As long as the index is defined in indexes.conf, you can move and rename it.
So yes.

0 Karma

yannK
Splunk Employee
Splunk Employee

Why not emptying the dispatch folder instead,
Or run your searches over a smaller time range ?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Drivers: How We're Streaming Real-Time F1 Telemetry Directly into Splunk ...

Data Drivers: Every Lap Tells a Story The Spectacle Two F1 racing sims go head-to-head on the .conf26 show ...

Data Management Digest – July 2026

  Welcome to the July 2026 edition of Data Management Digest! As your trusted partner in data innovation, the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...