Yes, you can mix SSDs and HDDs on the same server. Splunk doesn't care as long as the IOPS meet the minimum requirements. The recommendation is the fastest disk(s), usually SSDs, be used for writing (hot buckets) and the most-frequently used data. Everything else can go on slower disks, usually HDDs. The details about buckets are good to know, but aren't much of a factor in the hardware, aside from the above. Do keep your Splunk directories on separate mount points from the OS. The SH does not have the same I/O demands as the indexers.
... View more