I have a new instance of Splunk Enterprise installed on a Win 2016 server. It is set up as the OS is on the smaller but faster C drive and data is on the larger but slower D drive. How do I get splunk to store its data on the D drive while it is installed on the C drive?
The storage location is determined in the index configuration. https://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Configureindexstorage
This link doesn't show how to make the changes in a windows environment.
Try something like the following. $SPLUNK_DB should be %SPLUNK_DB% for windows, so you could try that as well.
homePath = E:\SplunkIndexes-warm\myindex\db
coldPath = F:\SplunkIndexes-cold\myindex\colddb
thawedPath = F:\SplunkIndexes-thawed\myindex\thaweddb