Getting Data In

Indexer almost out of storage space

kmcconnell
Path Finder

I'm about to run out of room on one of our indexers. We have two indexers setup and we are doing distributed indexing. I had an additional 2TB drive added to the one indexer, but I’m wondering if we need to add an additional drive to the other indexer. My plan was to modify the indexes.conf and start sending the two largest indexes cold storage to the new drive (like below). I assume I would copy the “index_to_change\colddb” folder structure to the new drive also. If I’m missing something or going about this wrong, please let me know. I’m pretty new at Splunk and I’m still learning.

[volume:primary]
path = D:\splunkdata
maxVolumeDataSizeMB = 1990000

[volume:cold]
path = E:\splunkdata
maxVolumeDataSizeMB = 1990000

[index_to_change]
homePath = volume:primary/defaultdb/db
coldPath = volume:cold/defaultdb/colddb

Tags (1)
0 Karma
1 Solution

_d_
Splunk Employee
Splunk Employee

That should work but it is advisable that all indexers (2 in your case) are configured identically.

View solution in original post

0 Karma

_d_
Splunk Employee
Splunk Employee

That should work but it is advisable that all indexers (2 in your case) are configured identically.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...