Splunk® Enterprise

Managing Indexers and Clusters of Indexers

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.

Configure the GCS remote store for SmartStore

Before you configure SmartStore settings on the indexers, you must ensure that your remote store is properly set up, so that it is available to the indexers.

Later, when you configure remote volumes for SmartStore, you configure settings specific to the remote store in indexes.conf. The indexer uses those settings to communicate with the remote store.

Supported remote storage services

Supported remote storage services include GCS, AWS S3, and Microsoft Azure Blob storage. For information on S3, see Configure the S3 remote store for SmartStore. For information on Azure Blob storage, see Configure the Azure Blob remote store for SmartStore

Configure a GCS remote store

When configuring GCS buckets:

  • The indexers' Compute Engine service account must have read, write and delete permissions for the GCS buckets that the indexers are associated with..
  • Provision the buckets to run in the same GCP region as the indexer Compute Engine instances.

See the Google GCS documentation for information on on how to create and configure buckets.

For GCS-specific settings available through Splunk Enterprise, search for settings in the indexes.conf spec file that start with remote.gs.

For information on security-related settings, such as settings for GCS authentication and encryption, see SmartStore on GCS security strategies.

Last modified on 26 July, 2021
Configure the S3 remote store for SmartStore   Configure the Azure Blob remote store for SmartStore

This documentation applies to the following versions of Splunk® Enterprise: 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters