Splunk Enterprise

separate nfs mounts for frozen vs. one NFS mount for multiple indexers

jcgever
Explorer

We are moving to a new storage array for our frozen data. Our old array is setup where our indexers have separate nfs mounts for the frozen data. Would there be an issue of having 5 indexers pointing to separate folders on one NFS mount or would it be best for each indexer to have separate NFS mounts for their frozen storage?

Labels (2)
Tags (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @jcgever,

Since Splunk will just copy frozen buckets, there will be no issue.

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...