All Apps and Add-ons

Are there plans for splunk to support zfs?


I tried running Splunk from within a zfs pool on FreeBSD 8.1 and it failed with a file system not supported error. Seeing that Splunk downloads are available for Solaris and FreeBSD, are there any plans for Splunk to be able to run from within a zfs pool or is that not feasible?

Tags (1)

Path Finder

We are looking to use ZFS. Is there any update on this or has anyone opened an enhancement request yet?

0 Karma


I'm running splunk-6.0.2-196940-freebsd-7.3-amd64.tgz on a 9.1-RELEASE system, on a zfs volume and I have not had any problems

0 Karma


I too just installed Splunk on a new FreeBSD 9.0 server using zfs as my boot/os volume. To my dismay, Splunk cannot use zfs.

The suggested solutions are not ideal, can Splunk please support a filesystem that has been strongly marketed and recommended by the FreeBSD team?

0 Karma



You can avoid the problem by creating a UFS filesystem on a ZFS partition.

zfs create -V 10g tank/ufs
newfs /dev/zvol/tank/ufs
mkdir /ufs
mount /dev/zvol/tank/ufs /ufs

Hope this helps,



It's a bug in the locktest binary. It doesn't actually test locking at all; it just has a whitelist of known filesystems, and if your fs isn't in that list, it fails. Two workarounds:

  1. Use a binary editor on the locktest binary and replace one of the filesystems in the list ("nfs" for example) with "zfs".

  2. Use LD_PRELOAD to pull in a shared object that wraps the fsstat() syscall and replaces "zfs" with "ufs". Luckily I created one to work around a similar bug in Symantec Netbackup 🙂 If you build the shared object from this post, all you need to do is add

export LD_PRELOAD=/usr/local/lib/

to your startup script, and splunk should work fine.

New Member

I can verify that splunk on ZFS in freebsd doesn't work.

Could not create a lock in the
SPLUNK_DB directory. Filesystem type
is not supported: buf.f_fstypename =
zfs If supporting this filesystem type
is important to you, please file an
Enhancement Request with Splunk
Support with the fs info number
listed. Locking test failed on
filesystem in path
/usr/local/splunk/var/lib/splunk with
code '9'. Please file a case online


SplunkIndexer# uname -a FreeBSD
SplunkIndexer 8.1-RELEASE FreeBSD
8.1-RELEASE #0: Mon Jul 19 02:36:49 UTC 2010
amd64 SplunkIndexer#

To confirm compat6x is install:

SplunkIndexer# pkg_info -a | grep
compat Information for

0 Karma

Splunk Employee
Splunk Employee

Splunk does support ZFS on Solaris:

However, we do not officially support ZFS on FreeBSD. That said, if you have the compat6x package installed I would be surprised if we can't get a lock on the filesystem.

Get Updates on the Splunk Community!

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...

Understanding Generative AI Techniques and Their Application in Cybersecurity

Watch On-Demand Artificial intelligence is the talk of the town nowadays, with industries of all kinds ...