Deployment Architecture

Recommendations for OS partitions, mount points and RAID configuration for linux servers

amruthamkumar
Observer

planning to deploy a splunk architecture with one SH and indexer cluster with 100GB/day data ingestion. Are there any recommendation documentations for OS partitions (paths with size), mount points and RAID configuration for linux servers.

Labels (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Some general recommendations:

  • Keep the OS, $SPLUNK_HOME, and $SPLUNK_DB on separate mount points
  • Don't use NFS
  • Avoid RAID 0
  • Use a supported file system
  • Partition size depends on the instance type and the amount of data to be stored.  300GB is recommended for non-indexers.  Indexer storage needs depend on index retention, replication, and use of SmartStore.
---
If this reply helps you, Karma would be appreciated.
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well... One could argue about the "don't use RAID0" (which actually isn't a RAID because there is no redundancy) since with RF>1 you provide redundancy at the whole cluster's level. But that's something we could debate long over a beer if I ever go to .conf 🙂

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I try to avoid RAID0 because loss of a single disk takes down the entire array.  I won't be bitten by that again.

---
If this reply helps you, Karma would be appreciated.
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Of course. With a single disk installation a single disk also takes down whole machine 😉

But seriously - it's just a matter of risk and cost management. Some users can accept the risk of the whole machine going down knowing that the machine is cheaper (and possibly a bit faster). But I agree, the storage is relatively cheap nowadays.

One important caveat: I'm of course talking about components which are replicated (indexers, search heads). You probably don't want a RAID0-based machine as CM.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...