Splunk Search

Linux Indexer root partition 100% full

johnklaiber
New Member

I had a previous case open on this (#1591420) but cannot seem to find it anymore.

In there Joe Love validated my idea to implement a move of our Splunk DB to a much larger partition and update Splunk config.

The referenced solution was the "easiest method' in this support case:
https://answers.splunk.com/answers/210748/splunk-amazon-ami-is-using-the-root-partition-to-s.html

As I was looking to implement this "easiest method" solution, for some reason our latest version of Splunk does not have the "/opt/splunk/splunk-launcher.cfg" file. We are version 7.3.0, has something changed since this original posting?

In fact, the .cfg files I see are in /etc and most are log- files. Is there a new file for updating the SPLUNK_DB= value?

Tags (1)
0 Karma

soumyasaha25
Contributor

as per this doc the splunk-launch.conf file should be in "$SPLUNK_HOME/etc/ " directory.

if you want to change the location of SPLUNK_DB change it in splunk-launch.conf

NOTE:
This conf file is different from most splunk conf files. There is only one in the whole system, located at $SPLUNK_HOME/etc/splunk-launch.conf; further, there are no stanzas, explicit or implicit. Finally, any splunk-launch.conf files in etc/apps/... or etc/users/... will be ignored.

0 Karma

johnklaiber
New Member

Thank you. I did locate it and was able to restore functionality of the indexer.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...