Installation

Volume partitioning and smartstore

pBear
Explorer

We are running a  single Splunk Enterprise 8.1 instance on a Linux AWS EC2 instance. We are using smartstore backed by S3. We have /opt/splunk (including the index volume/cache) on a separate partition from the OS. 

I have not seen/found any documentation addressing OS level partitioning. 

Are there performance concerns with our current configuration? Would/could a spike in the size of non-index files on the splunk partition cause performance issues or caching abnormalities with smartstore?

Does it make sense to separate the indexes (./lib/) onto its own partition, separate from both the OS and splunk config/app/log and other transient files?

 

Labels (1)
0 Karma
1 Solution

pBear
Explorer

Thank you. 
It is as I expected. It makes perfect sense to me, regardless of smart-store or not. But I couldn't find any documentation I could point to in order to justify the architectural change to management. 

I guess they are just going to have to take our word for it. 🙂

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes!  $SPLUNK_HOME, $SPLUNK_DB, and the OS should be on separate partitions.

---
If this reply helps you, Karma would be appreciated.

pBear
Explorer

Thank you. 
It is as I expected. It makes perfect sense to me, regardless of smart-store or not. But I couldn't find any documentation I could point to in order to justify the architectural change to management. 

I guess they are just going to have to take our word for it. 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...