Deployment Architecture

should searchhead pooling or mounted knowledge bundles be writing to shared var directory?

tpsplunk
Communicator

I recently enabled searchhead pooling and mounted knowledge bundles using an NFS store mounted to /mnt/shp/ on each of my splunk servers. the {users,apps,system} directories are on /mnt/shp/etc/{users,apps,system}. i've noticed the searchheads have started writing to some "var" directories: /mnt/shp/var/run/splunk/{dispatch,lookup_tmp, rss, scheduler, srtemp}. I don't remember seeing this anywhere in the documentation. is it expected? what is it for? do the search peers (indexers) uses these directories with regards to mounted knowledge bundles?

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

the search heads use this to communicate scheduled jobs and job results with each other. the indexers don't care about this information though.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

the search heads use this to communicate scheduled jobs and job results with each other. the indexers don't care about this information though.

Get Updates on the Splunk Community!

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...