All Apps and Add-ons

How to increase Splunk Indexer Drive Space on windows Platform?

nnimbe1
Path Finder

Hi All,

We are having 2 Splunk Indexers which are installed on Windows 2012 R2 on D drive of capacity 2TB each, and both are on sink.(both indexers are on distributed environment)

Base OS is windows version is 6.3.1

Now Due to Space constraint, we need to increase the Space on both the indexers, hence we are thinking about 2 options:

  1. We are planning to attach one new 5 TB drive and to copy all the existing data(online) and configure it to 5 TB drive from 2 TB(existing) drive and post which delete the 2 TB drive.
    Please suggest whether it is possible, and how to achieve the same? Also if any downtime is required for the same? This is the primary option for us... And let me know whether we need to take any backup for the same.

  2. If the first option is not possible then we need to add one more new drive of 3 TB capacity and make it available and sink with existing 2 TB drive for searching and indexing.

Which option is to be preferred please suggest

0 Karma

nnimbe1
Path Finder

Can we use directly Dynamic disk and increase the indexer space drive

0 Karma

adonio
Ultra Champion

Hello there,

will recommend to go with option #2. try to avoid moving data after its been indexed
add the disk to the drives and you supposed to be good there.

hope it helps

0 Karma

nnimbe1
Path Finder

Thanks Adonio,

Now the question is can we directly add another drive when the application is up or we have to stop splunk service while adding and secondly how to make new drive indexable and sink with old drive for searching....

0 Karma

adonio
Ultra Champion

i think its more of a windows question. can you do it in windows without restating the os?
my guess is, no. therefore splunk will be down as well.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...