Installation

Move Splunk from C:\ to D:\ after installation

meghasingh
Engager

Hi Team,

We have installed Splunk on our server. By default it is located in C:\Program Files. However, we have now realized that the C:\ our server doesn't have enough space to be able to handle all of the logging and indexing that Splunk does. The free space runs out too soon and indexing stops. Therefore, we want to move Splunk from C:\ to D:\ drive. Are there any steps or procedures we can follow to make this work. What configuration settings should be updated to achieve this seamlessly. Please advise.

Tags (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

@meghasingh,

You shouldn't have to move "Splunk" itself to the new drive, just all the data files. Splunk's reasonably small. But it has subfolders that can be very large, and those are what you want to move. The folder is the one that has all your indexes in it.

Luckily for you, this isn't real hard.

There's a step by step doc on moving indexes , why not give that a shot and see if it answers all your questions?

If you have problems, be sure to mention them here - but know for now the instructions have you copy the files, so make backups of your configuration files before changing them and you should be able to recover back to the originals easily.

View solution in original post

Richfez
SplunkTrust
SplunkTrust

@meghasingh,

You shouldn't have to move "Splunk" itself to the new drive, just all the data files. Splunk's reasonably small. But it has subfolders that can be very large, and those are what you want to move. The folder is the one that has all your indexes in it.

Luckily for you, this isn't real hard.

There's a step by step doc on moving indexes , why not give that a shot and see if it answers all your questions?

If you have problems, be sure to mention them here - but know for now the instructions have you copy the files, so make backups of your configuration files before changing them and you should be able to recover back to the originals easily.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...