Deployment Architecture

Does Splunk support EXT4 yet?

maverick
Splunk Employee
Splunk Employee

Does Splunk support EXT4 file system? According to system requirements, EXT2/3 is supported.

Are there any benchmarks regarding iops to EXT4 as compared to, say, XFS?

I believe RHEL 5.6 x86_64 fully supports it and it would be nice to take advantage of the I/O improvements it offers, if there is an advantage.

the_wolverine
Champion

EXT4 is supported now.

au_chrismor
Explorer

My experience with 4.3 on OpenSUSE 12.1 (x64) has been no problems to report, and no appreciable performance change over ext3 on the same hardware.

0 Karma

jrodman
Splunk Employee
Splunk Employee

Not tested, thus not officially supported.

Its unclear at this time if Splunk I/O patterns will show a noticeable improvement on ext4 or a major improvement or nada. I suspect the results will be in the single digit percentage points.

For external folks, file enhancement requests if you are interested in this, each one will count.

For internal (field) folks, file enhancement requests, and optionally contact product management.

Its been filed as at least ENH-4281 and ENH-4288 already.


Update: Apparently a tipping point was reached and it is planned for a future release (subject to change as always).

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...