Splunk Enterprise

How to fix frozen folder not splitting up by indexes that instead have $_index_name at the root folder on the volume?

avivfri
Explorer

Hello

I noticed that my frozen folder are not splitting up by indexes. Instead I have "$_index_name" at the root folder on the volume.

this is my configuration:

 

[default]
maxTotalDataSizeMB = 1000000
frozenTimePeriodInSecs = 13824000
homePath = volume:hot/$_index_name/db
coldPath = volume:cold/$_index_name/colddb
tstatsHomePath = volume:hot/$_index_name/datamodel_summary
summaryHomePath = volume:hot/$_index_name/summary
thawedPath = $SPLUNK_DB/$_index_name/thaweddb
coldToFrozenDir = /frozen/$_index_name/frozendb
repFactor=auto

 

is there a way to fix it?

Thank you

Labels (2)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

The docs to indexes.conf suggest that the placeholder $_index_name is _not_ supported for the coldToFrozenDir setting. So you'd have to overwrite it to a specific value for each index.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

The docs to indexes.conf suggest that the placeholder $_index_name is _not_ supported for the coldToFrozenDir setting. So you'd have to overwrite it to a specific value for each index.

Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...