Hi,
We're currently using Splunk on Solaris with ZFS as the underlying filesystem. As you may know, ZFS offers filesystem base compression and we can also choose between different compression algorythms..
Since it usually is a bad idea to try to compress data twice, I was looking for a way to disable Splunk's index compression so I can validate if there are gains to be made by using ZFS compression.
This being said, I also think it could be useful for people using NAS solutions that are based on ZFS (Sun's ZFS appliance, Nexenta's solutions, SGI's nas, etc). This would let the storage device deals with compression and leave as much cpu as possible for the indexer.
... View more