Deployment Architecture

Before planning to deploy a Distributed Search environment, is there a partition model recommendation before installing Splunk 6.4 on my Linux servers?

Jrubalcaba
Explorer

I am planning to deploy a Splunk Distributed Search Architecture in a mixed environment of 500 servers mostly Windows and some Red Hat Enterprise (RHEL) Linux 7. Splunk hosts will be RHEL 7.2 I will have two search heads: Enterprise & Security, a 3 node indexer clustered on the Splunk application level, and a separate Deployment Server.

I read that Splunk will create the necessary directories during installation. Is there partition model recommendation or LVM I should have ready before installing Splunk 6.4 in my Linux servers? Or should I just let Splunk create directories automatically during install?

See my current Linux partitions below:

/root           50G
/home/  200 G
/boot    500mb
/swap/   8G
/tmp
/var
/var/tmp/
/var/log/
/var/log/audit/

ddrillic
Ultra Champion

You probably should let Splunk install itself under /opt/splunk and let it create its directories.

Special attention is usually needed for the indexer's file system. Usually, we would point it to a distinct file system such as /SplunkIndexData with high capacity based on your needs.

dstonecypher_sp
Splunk Employee
Splunk Employee

Go with whatever your sysadmins are used to, except put /opt/splunk on its own partition if and only if that makes backups or recovery easier for you.

On an indexer, I suggest making sure your index location (either /opt/splunk/var/lib/splunk/, or /data/, or whatever) its own partition, too.

As for directories, just let Splunk do it. The only thing you may need to do by hand is the index location on the indexers, if not using the default.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...