Deployment Architecture

Any reason why Splunk couldn't use something like gluster as a storage option?

dskillman
Splunk Employee
Splunk Employee

Has anyone had any experience with clustered storage like gluster? gluster.org

Tags (2)
0 Karma

arnedietrichsta
Explorer

While researching my zfs problem, I stumbled over this: http://martinliu.cn/workshop-redhat-storage-splunk/
It seems that this does the trick:
echo OPTIMISTIC_ABOUT_FILE_LOCKING = 1 >> /opt/splunk/etc/splunk-launch.conf

0 Karma

rsigle
Explorer

I'm still in my initial testing, but gluster works if you mount the glusterfs via nfs locally. This isn't exactly ideal but seems to work better than straight NFS if you have good network connectivity and fast local storage. I've tested with both splunk 4.3 and 5.0.1. performance in 5.0.1 is comparable to standalone search heads.

0 Karma

lukeh
Contributor

I couldn't get search head pooling to work with gluster 3.2.5 😞

Error in search head pooling enable: Failed to lock /mnt/splunk/etc/etc/users/testpath with return code -1: File exists

I logged a call with Splunk support and they confirmed that it is not supported... feature request submitted.

I'm going to use DRBD in the meantime, but gluster would have been way better!

Luke 🙂

0 Karma

Lowell
Super Champion

Does it pass according to the locktest utility?

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...