Getting Data In

What is the best way to partition RAID 10 Disk of 20TB for Hot/Warm/Cold Buckets on each indexer in an indexer cluster?

daniel_augustyn
Contributor

I have about 20TB of disk space for each indexer in a cluster deployment with the total of two indexers. What are the best ways to partition this much space for hot/warm/cold buckets? Should I also stick with one bigger RAID 10 deployment for all of these buckets, or should I divide it for hot bucket for writing (1st RAID) and warm/cold buckets for searching (2nd RAID)?

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

I'd do one big 1+0 per indexer, then moving warm to cold will only be a rename and not an actual copy.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

I'd do one big 1+0 per indexer, then moving warm to cold will only be a rename and not an actual copy.

sowings
Splunk Employee
Splunk Employee

I'll +1(0) that!

daniel_augustyn
Contributor

Thanks, that's what we were thinking would be the best solution.

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese and ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...