Splunk Search

Linux Indexer root partition 100% full

johnklaiber
New Member

I had a previous case open on this (#1591420) but cannot seem to find it anymore.

In there Joe Love validated my idea to implement a move of our Splunk DB to a much larger partition and update Splunk config.

The referenced solution was the "easiest method' in this support case:
https://answers.splunk.com/answers/210748/splunk-amazon-ami-is-using-the-root-partition-to-s.html

As I was looking to implement this "easiest method" solution, for some reason our latest version of Splunk does not have the "/opt/splunk/splunk-launcher.cfg" file. We are version 7.3.0, has something changed since this original posting?

In fact, the .cfg files I see are in /etc and most are log- files. Is there a new file for updating the SPLUNK_DB= value?

Tags (1)
0 Karma

soumyasaha25
Contributor

as per this doc the splunk-launch.conf file should be in "$SPLUNK_HOME/etc/ " directory.

if you want to change the location of SPLUNK_DB change it in splunk-launch.conf

NOTE:
This conf file is different from most splunk conf files. There is only one in the whole system, located at $SPLUNK_HOME/etc/splunk-launch.conf; further, there are no stanzas, explicit or implicit. Finally, any splunk-launch.conf files in etc/apps/... or etc/users/... will be ignored.

0 Karma

johnklaiber
New Member

Thank you. I did locate it and was able to restore functionality of the indexer.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...