Getting Data In

indexes.conf and setting volumes globally

himynamesdave
Contributor

Hi -

I am re-architecting our Splunk environment. I have mounted various volumes to each of my indexers (3 total) for hot, warm and cold buckets.

To do this I have set volumes in an indexes.conf file I will deploy via Deployment Server to the 3 indexers.

/deployment-apps/myapp/default/indexes.conf

[volume:hot_warm]
path = /splunk_data/hot_warm
#DISK SIZE = 2.9TB
maxVolumeDataSizeMB = 2800000

[volume:cold]
#DISK SIZE = 8.8TB
path = /splunk_data/cold
maxVolumeDataSizeMB = 8700000

My question is, will this config set volumes globally for all indexes on the indexer? That is, if another app has an index=x, will that index write hot data to the path; "/splunk_data/hot_warm", for example?

0 Karma
1 Solution

brreeves_splunk
Splunk Employee
Splunk Employee

As long as when you set up homePath=volume:hot_warm/indexname/db/ in each indexes.conf for each index, then yes. homePath is a required value, so that should be easy.

All you've done so far is tell Splunk that there ARE volumes...you haven't yet told an index to use them.

View solution in original post

brreeves_splunk
Splunk Employee
Splunk Employee

As long as when you set up homePath=volume:hot_warm/indexname/db/ in each indexes.conf for each index, then yes. homePath is a required value, so that should be easy.

All you've done so far is tell Splunk that there ARE volumes...you haven't yet told an index to use them.

himynamesdave
Contributor

Is there anyway to set the path to the volumes globally for each indexer, so that each index uses these volumes by default for the appropriate bucket?

brreeves_splunk
Splunk Employee
Splunk Employee

I corrected my original answer, but you already HAVE told Splunk that the volumes exist, but the homePath value is required PER index...so not really a way to set that globally. You should have indexes.conf that get deployed with the apps as well where you could update the homePath.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...