For a 100% Virtual Environment:
I am planning to deploy Splunk 6.5 under Linux RHEL 7.2 in a Distributed Search Architecture. My indexers are going to be clustered with the Splunk application. I am performing capacity planning for HOT/COLD buckets at each indexer. I will have two NON-Clustered Search Heads .
For both Search Heads, do I need to apply the same HOT/COLD bucket principle or can I just assign a local disk as part of the VMDK for storage?
I will appreciate any feedback,
Thanks,
Jordi
... View more