Deployment Architecture

Splunk 5 Clusters and storage question

responsys_cm
Builder

Assume I have a cluster of three indexers. They each have an array of SSDs and an array of SAS disks. The cluster would be configured for single redundancy of data. I would want to configure the hot/warm location of my critical indexes to run on the SSDs.

When the cluster members replicate data from buckets on the SSDs, is there any way to control where the redundant copy of the data goes? Can I store my redundant data on the slower, cheaper disks?

Thanks.

Craig

Tags (1)
1 Solution

mahamed_splunk
Splunk Employee
Splunk Employee

In Splunk 5.0, the replicated copies always live in the colddb path. So if you configure your Cold path on slower disks, then you will get the behavior you are looking for.

View solution in original post

mahamed_splunk
Splunk Employee
Splunk Employee

In Splunk 5.0, the replicated copies always live in the colddb path. So if you configure your Cold path on slower disks, then you will get the behavior you are looking for.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...