Installation

Volume partitioning and smartstore

pBear
Explorer

We are running a  single Splunk Enterprise 8.1 instance on a Linux AWS EC2 instance. We are using smartstore backed by S3. We have /opt/splunk (including the index volume/cache) on a separate partition from the OS. 

I have not seen/found any documentation addressing OS level partitioning. 

Are there performance concerns with our current configuration? Would/could a spike in the size of non-index files on the splunk partition cause performance issues or caching abnormalities with smartstore?

Does it make sense to separate the indexes (./lib/) onto its own partition, separate from both the OS and splunk config/app/log and other transient files?

 

Labels (1)
0 Karma
1 Solution

pBear
Explorer

Thank you. 
It is as I expected. It makes perfect sense to me, regardless of smart-store or not. But I couldn't find any documentation I could point to in order to justify the architectural change to management. 

I guess they are just going to have to take our word for it. 🙂

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes!  $SPLUNK_HOME, $SPLUNK_DB, and the OS should be on separate partitions.

---
If this reply helps you, Karma would be appreciated.

pBear
Explorer

Thank you. 
It is as I expected. It makes perfect sense to me, regardless of smart-store or not. But I couldn't find any documentation I could point to in order to justify the architectural change to management. 

I guess they are just going to have to take our word for it. 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...