Okay we'll try this. I changed the index.conf file (all it had was default, "Server name" below it) not sure if this is the correct index.conf file (there seem to be many in different locations?) I think mine was at c:\program files\Splunk\var\local , I changed the system name to the system I plan on installing Splunk on. We having a very basic barebones install....Splunk enterprise default everything and all we ingest is application, security, system, forwarder event logs (that's the default configuration that Splunk applies) and we configure it to use receiving indexer (no deployment servers) and port 9997 (default) on enterprise receiving indexer port #. Then we have our dashboards to filter and display the data we want for review. Does it matter that the location of the Splunk folder will change from c:\program files\ to a data drive --> d\Splunk (a storage drive ) When I do the Splunk install of enterprise I will change the location to the D drive (where we copied the initial c:\program Files\Splunk folder from original machine) and hopefully it will work. If you have an idea of the file location (default location) of where that index file is that would be helpful. The main reason we are doing this is that our Splunk server is currently on a workstation with a 256gb HD and our Splunk folder is 100 gigabytes, so we want to move it to a file server data drive and have it operate off that. Thanks again!
... View more