I've looked a little closer at the current configuration (this is stuff I've inherited at my new position, so I'm still familiarizing myself with it) and I have more details.
I'll use actual file paths here to avoid confusing anybody.
I'm working on an index called os, which has homePath=/splunk/data/hot/os/db, and coldPath=/splunk/data/hot/os/colddb. Both of these directories have over 300 buckets in them. When I changed the indexes.conf to include the volumes:
[volume:hot_warm]
path = /splunk/data/hot
maxVolumeDataSizeMB = 3500000
[volume:cold]
path = /splunk/data/cold
maxVolumeDataSizeMB = 6500000
and to use homePath and coldPath as:
[os]
repFactor=auto
homePath = volume:hot_warm/os
coldPath = volume:cold/os
thawedPath = /splunk/data/thawed/os_thawed
Once these changes were made and the indexer was restarted, /splunk/data/cold/os was created as a directory, but nothing was ever moved, or added to it. I've now realized that /splunk/data/hot/os/colddb is what holds all of my cold data, but how do I get splunk to move all of that data to /splunk/data/cold/os?
... View more