<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Index filesystem recommendations in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Index-filesystem-recommendations/m-p/360288#M3144</link>
    <description>&lt;P&gt;Hello all! Happy new year. I have my splunk indexes going to a filesystem that is XFS with the following mount options:&lt;/P&gt;

&lt;P&gt;/dev/md0 on /opt/splunk type xfs (rw,relatime,attr2,inode64,sunit=1024,swidth=4096,noquota)&lt;/P&gt;

&lt;P&gt;I am seeing performance issues and do want to leave no stone unturned. What are peoples thoughts on these mount options? What should I change if any?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jan 2018 16:35:05 GMT</pubDate>
    <dc:creator>brent_weaver</dc:creator>
    <dc:date>2018-01-02T16:35:05Z</dc:date>
    <item>
      <title>Splunk Index filesystem recommendations</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Index-filesystem-recommendations/m-p/360288#M3144</link>
      <description>&lt;P&gt;Hello all! Happy new year. I have my splunk indexes going to a filesystem that is XFS with the following mount options:&lt;/P&gt;

&lt;P&gt;/dev/md0 on /opt/splunk type xfs (rw,relatime,attr2,inode64,sunit=1024,swidth=4096,noquota)&lt;/P&gt;

&lt;P&gt;I am seeing performance issues and do want to leave no stone unturned. What are peoples thoughts on these mount options? What should I change if any?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jan 2018 16:35:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Index-filesystem-recommendations/m-p/360288#M3144</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2018-01-02T16:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Index filesystem recommendations</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Index-filesystem-recommendations/m-p/360289#M3145</link>
      <description>&lt;P&gt;Concerning these mount options, I think that those would be fine.  My only concern would be the sunit and swidth options, which should be set based on the hardware RAID options that you are using.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://xfs.org/index.php/XFS_FAQ#Q:_How_to_calculate_the_correct_sunit.2Cswidth_values_for_optimal_performance"&gt;http://xfs.org/index.php/XFS_FAQ#Q:_How_to_calculate_the_correct_sunit.2Cswidth_values_for_optimal_performance&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:52:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Index-filesystem-recommendations/m-p/360289#M3145</guid>
      <dc:creator>simon_branton_h</dc:creator>
      <dc:date>2018-01-12T17:52:03Z</dc:date>
    </item>
  </channel>
</rss>

