New Member


I'm setting up Splunk on a Windows Server 2008 box with a 8 drives in a RAID 10. I am curious if it is better to use a single disk partition or if there is an advantage to breaking up the drives into 2 partitions (one for the OS/Apps and one for data).

Splunk documentation seems to indicate a single disk partition is preferred. This is an excerpt :

Splunk can use multiple disks and
partitions for its index data. It's
possible to configure Splunk to use
many disks/partitions/filesystems on
the basis of multiple indexes and
bucket types, so long as you mount
them correctly and point to them
properly from indexes.conf. However,
we recommend that you use a single
high performance file system to hold
your Splunk index data for the best

Is there any advantage of using two disk partitions over one?


0 Karma

Splunk Employee
Splunk Employee

Splunk does not enforce or recommend a specific partitioning.

Usually from an operations point of view you seperate operating system stuff from data.

So create a single RAID1 for OS+Splunk basic stuff and put the indexes on a seperate RAID10 which is able to deliver 800IOPS+.



0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!