<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Slow performance Splunk 6.0.1 Master Head with Splunk 5.0.2 Indexer in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160313#M23207</link>
    <description>&lt;P&gt;The same query was run in two master heads. These are the results:&lt;/P&gt;

&lt;P&gt;Response time from master head Splunk 5.0.2:&lt;/P&gt;

&lt;P&gt;This search has completed and has returned 12 results by scanning 41,283 events in 11.072seconds. -&amp;gt; &lt;BR /&gt;
9.604 seconds    dispatch.stream.remote&lt;/P&gt;

&lt;P&gt;Response time from master head splunk 6.0.1:&lt;/P&gt;

&lt;P&gt;This search has completed and has returned 12 results by scanning 41,283 events in208.412 seconds.&lt;BR /&gt;
200.562  dispatch.finalizeRemoteTimeline&lt;/P&gt;

&lt;P&gt;The same behavior across all splunk 6.0.1 master head but not in splunk 5.0.2 master head. &lt;/P&gt;

&lt;P&gt;Is there anyone in the forum with the same problem?&lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;

&lt;P&gt;Lp&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2014 00:21:00 GMT</pubDate>
    <dc:creator>lpolo</dc:creator>
    <dc:date>2014-02-21T00:21:00Z</dc:date>
    <item>
      <title>Slow performance Splunk 6.0.1 Master Head with Splunk 5.0.2 Indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160313#M23207</link>
      <description>&lt;P&gt;The same query was run in two master heads. These are the results:&lt;/P&gt;

&lt;P&gt;Response time from master head Splunk 5.0.2:&lt;/P&gt;

&lt;P&gt;This search has completed and has returned 12 results by scanning 41,283 events in 11.072seconds. -&amp;gt; &lt;BR /&gt;
9.604 seconds    dispatch.stream.remote&lt;/P&gt;

&lt;P&gt;Response time from master head splunk 6.0.1:&lt;/P&gt;

&lt;P&gt;This search has completed and has returned 12 results by scanning 41,283 events in208.412 seconds.&lt;BR /&gt;
200.562  dispatch.finalizeRemoteTimeline&lt;/P&gt;

&lt;P&gt;The same behavior across all splunk 6.0.1 master head but not in splunk 5.0.2 master head. &lt;/P&gt;

&lt;P&gt;Is there anyone in the forum with the same problem?&lt;/P&gt;

&lt;P&gt;Any idea?&lt;/P&gt;

&lt;P&gt;Lp&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2014 00:21:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160313#M23207</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2014-02-21T00:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Slow performance Splunk 6.0.1 Master Head with Splunk 5.0.2 Indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160314#M23208</link>
      <description>&lt;P&gt;I found this:&lt;/P&gt;

&lt;P&gt;Remote timeline feature can reduce performance&lt;BR /&gt;
A 6.x search head by default asks its search peers to generate a remote timeline. This isn't a problem with 6.x search peers, but 5.x search peers won't know how to generate the timeline. As a result, searches can slow dramatically.&lt;BR /&gt;
The workaround is to add the following attribute to limits.conf on the search head :&lt;BR /&gt;
[search]&lt;BR /&gt;
remote_timeline_fetchall = false&lt;BR /&gt;
After making this change, you must restart the search head.&lt;BR /&gt;
Important: You should remove this attribute after all search peers have been upgraded to 6.x.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:56:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160314#M23208</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2020-09-28T15:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Slow performance Splunk 6.0.1 Master Head with Splunk 5.0.2 Indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160315#M23209</link>
      <description>&lt;P&gt;All Indexers were upgraded to Splunk 6.0.1. however, the response time from the master head 6.0.1 continues to be slower compared to splunk 5.0.2 master head. &lt;BR /&gt;
For the sake of clarity, both master heads are running with the same type of hardware.&lt;BR /&gt;
Open case with splunk tech support. &lt;BR /&gt;
any idea?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2014 15:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160315#M23209</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2014-02-21T15:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: Slow performance Splunk 6.0.1 Master Head with Splunk 5.0.2 Indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160316#M23210</link>
      <description>&lt;P&gt;this is the solution to this problem:&lt;/P&gt;

&lt;P&gt;Make the following changes in &lt;BR /&gt;
/$splunkHome$/etc/system/local/limits.conf&lt;/P&gt;

&lt;P&gt;[search]&lt;BR /&gt;
remote_timeline_fetchall = 0&lt;BR /&gt;
fetch_remote_search_log = false&lt;/P&gt;

&lt;P&gt;then restart splunkd&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160316#M23210</guid>
      <dc:creator>lpolo</dc:creator>
      <dc:date>2020-09-29T11:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Slow performance Splunk 6.0.1 Master Head with Splunk 5.0.2 Indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160317#M23211</link>
      <description>&lt;P&gt;Trying to get a handle on what "generate a remote timeline" means-- what's the effect of disabling this? &lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2016 17:52:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Slow-performance-Splunk-6-0-1-Master-Head-with-Splunk-5-0-2/m-p/160317#M23211</guid>
      <dc:creator>rabitoblanco</dc:creator>
      <dc:date>2016-04-29T17:52:52Z</dc:date>
    </item>
  </channel>
</rss>

