<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best practices for search optimization for Splunk Cloud? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Cloud/m-p/482511#M8589</link>
    <description>&lt;P&gt;Does anyone have best practices to help optimize searches for Splunk Cloud? &lt;/P&gt;</description>
    <pubDate>Mon, 16 Sep 2019 15:18:14 GMT</pubDate>
    <dc:creator>adukes_splunk</dc:creator>
    <dc:date>2019-09-16T15:18:14Z</dc:date>
    <item>
      <title>Best practices for search optimization for Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Cloud/m-p/482511#M8589</link>
      <description>&lt;P&gt;Does anyone have best practices to help optimize searches for Splunk Cloud? &lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 15:18:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Cloud/m-p/482511#M8589</guid>
      <dc:creator>adukes_splunk</dc:creator>
      <dc:date>2019-09-16T15:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices for search optimization for Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Cloud/m-p/482512#M8590</link>
      <description>&lt;H2&gt;&lt;EM&gt;The Splunk Product Best Practices team provided this response. Read more about &lt;A href="https://www.splunk.com/blog/2019/02/25/how-crowdsourcing-is-shaping-the-future-of-splunk-best-practices.html"&gt;How Crowdsourcing is Shaping the Future of Splunk Best Practices&lt;/A&gt;.&lt;/EM&gt;&lt;/H2&gt;

&lt;H1&gt;Better. Stronger. Faster.&lt;/H1&gt;

&lt;P&gt;Splunk works fine out of the box. As you increase load on your system, though, you'll want to get familiar with ways to enhance its ability to handle that load. We’ll show you how to identify the cause of slow searches and review possible trouble spots in your deployment.&lt;/P&gt;

&lt;H1&gt;How search optimization helps you do more with less&lt;/H1&gt;

&lt;P&gt;Slow searches can be caused by inefficient search practices, but they can also be caused by poor data quality. You can find remarkable performance improvements when you resolve things like the incorrect event breaks and time stamp errors in the data. Inefficiencies like these can cause indexers to work overtime both when indexing data and finding the search results. If your searches run more efficiently, they also run faster and complete sooner. Which means the system can handle more of them in the same time!&lt;/P&gt;

&lt;H1&gt;Things to know&lt;/H1&gt;

&lt;P&gt;Use Splunk Cloud Monitoring Console (CMC) &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/latest/User/DMCoverview#Dashboards"&gt;dashboards&lt;/A&gt; to determine if any searches have performance issues that need attention. The CMC enables you to &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/latest/User/DMCoverview"&gt;monitor Splunk Cloud deployment health&lt;/A&gt; and to &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/User/DMCoverview#Self-service_Splunk_Cloud:_Enable_platform_alerts"&gt;enable platform alerts&lt;/A&gt;. You can modify existing alerts or create new ones. You can interpret results in these &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Viz/WebFramework"&gt;dashboards&lt;/A&gt; to identify ways to optimize and troubleshoot your deployment.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Search Usage Statistics&lt;/STRONG&gt;: This dashboards shows search activity across your deployment with detailed information broken down by instance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Scheduler Activity&lt;/STRONG&gt;: This dashboard shows Information about scheduled search jobs (reports) and you can &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/latest/Report/Configurethepriorityofscheduledreports"&gt;configure the priority of scheduled reports&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Forwarders: Instance and Forwarders: Deployment&lt;/STRONG&gt;: These dashboards show information about forwarder connections and status. Read about how to &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Receiverconnection"&gt;troubleshoot forwarder/receiver connection&lt;/A&gt; in &lt;STRONG&gt;&lt;EM&gt;Forwarding Data&lt;/EM&gt;&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/UL&gt;

&lt;H1&gt;Things to do&lt;/H1&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Access the Splunk Cloud Monitoring Console (CMC)&lt;/STRONG&gt;. &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/latest/User/DMCoverview"&gt;Monitor Splunk Cloud deployment health&lt;/A&gt; and &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/User/DMCoverview#Self-service_Splunk_Cloud:_Enable_platform_alerts"&gt;enable platform alerts&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Improve your source types&lt;/STRONG&gt;. Review the data quality dashboards to identify and &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Resolvedataqualityissues"&gt;resolve data quality issues&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Check the HTTP Event Collection Status&lt;/STRONG&gt;: If you have &lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/latest/Data/UsetheHTTPEventCollector"&gt;set up and use HTTP Event Collector&lt;/A&gt; to monitor the progress of a token.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=9awwyjORWO8" target="_blank"&gt;&lt;IMG alt="Using the Splunk HTTP Event Collector (HEC)" src="https://i.ytimg.com/vi/9awwyjORWO8/hqdefault.jpg" /&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 15:20:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Cloud/m-p/482512#M8590</guid>
      <dc:creator>adukes_splunk</dc:creator>
      <dc:date>2019-09-16T15:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices for search optimization for Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Cloud/m-p/482513#M8591</link>
      <description>&lt;P&gt;Added related video. &lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 17:27:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Cloud/m-p/482513#M8591</guid>
      <dc:creator>adukes_splunk</dc:creator>
      <dc:date>2019-10-21T17:27:38Z</dc:date>
    </item>
  </channel>
</rss>

