Splunk Dev

Archiving frozen data to network drive

sudhir7
Explorer

I am trying to archive data to the network drive, I have following stanza in my indexes.conf file.

[indexName]
frozenTimePeriodInSecs = 31622400
coldToFrozenDir = \\netwotkDrive\splunk\indexName\frozendb

This setting is not working for me.
Has anyone else faced a similar situation? Are there any configurational settings I am missing?

suamme1
Engager

I wasn't able to get this to work directly to a network folder as you posted. If you are still working on it, I ended up configuring a folder on each indexer that is a NTFS junction to a remote file share. This way, the splunk service writes as if it is a local file and NTFS takes care of the rest. I'm not sure if it's a supported solution, but my low-volume cluster has been running like this for several years with no apparent issues.

One thing to note with an indexer cluster is to point the junction to a different folder within the share for each machine to avoid naming collisions (IndexerA's junction should point to \server\share\indexerA and IndexerB's to \server\share\indexerB or some similar scheme).

0 Karma

dkeck
Influencer

Hi,

did you restart after changing this?

0 Karma

sudhir7
Explorer

@dkeck Yes.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...