Deployment Architecture

should searchhead pooling or mounted knowledge bundles be writing to shared var directory?

tpsplunk
Communicator

I recently enabled searchhead pooling and mounted knowledge bundles using an NFS store mounted to /mnt/shp/ on each of my splunk servers. the {users,apps,system} directories are on /mnt/shp/etc/{users,apps,system}. i've noticed the searchheads have started writing to some "var" directories: /mnt/shp/var/run/splunk/{dispatch,lookup_tmp, rss, scheduler, srtemp}. I don't remember seeing this anywhere in the documentation. is it expected? what is it for? do the search peers (indexers) uses these directories with regards to mounted knowledge bundles?

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

the search heads use this to communicate scheduled jobs and job results with each other. the indexers don't care about this information though.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

the search heads use this to communicate scheduled jobs and job results with each other. the indexers don't care about this information though.

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...