"Do keep your Splunk directories on separate mount points from the OS." - Yes that is the idea. We haven't implemented this yet though. Regarding search head - my idea is to keep read intensive operations (such as querying particular logs etc.) on SSDs, and allocate HDDs for offline report generation using Splunk pipeline/job features. I want to use SSDs for read intensive operations, and I want to use HDDs for read/write operations to reduce component failures. Now for indexers, Splunk has clearly outlined the policy for hot/warm/cold buckets, however for search heads, I see hints. Do you see any reference implementation for different types of disks in same server for indexers and search heads?
... View more