I recently learned, using SplunkAdmins app that I should disable Transparent Huge Pages on my Splunk Enterprise host.
However, I'm using the Splunk docker image, which I expect would include such a recommended configuration by default?
In any case, when trying to disable them, I'm getting an error that the file-system is readonly. There seems to be a solution to that - namely making the file-system writeable by remounting it.
Do you think the Splunk docker image should be modified to disable THP? Should I use the blunt solution of remounting the FS?