<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practices for search optimization for Splunk Enterprise? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Enterprise/m-p/482597#M8595</link>
    <description>&lt;H2&gt;&lt;EM&gt;The Splunk Product Best Practices team provided this response. Read more about &lt;A href="https://www.splunk.com/blog/2019/02/25/how-crowdsourcing-is-shaping-the-future-of-splunk-best-practices.html"&gt;How Crowdsourcing is Shaping the Future of Splunk Best Practices&lt;/A&gt;.&lt;/EM&gt;&lt;/H2&gt;

&lt;H1&gt;Better. Stronger. Faster.&lt;/H1&gt;

&lt;P&gt;Splunk works fine out of the box. As you increase load on your system, though, you'll want to get familiar with ways to enhance its ability to handle that load. We’ll show you how to identify the cause of slow searches and review possible trouble spots in your deployment.&lt;/P&gt;

&lt;H1&gt;How search optimization helps you do more with less&lt;/H1&gt;

&lt;P&gt;Slow searches can be caused by inefficient search practices, but they can also be caused by poor data quality. You can find remarkable performance improvements when you resolve things like the incorrect event breaks and time stamp errors in the data. Inefficiencies like these can cause indexers to work overtime both when indexing data and finding the search results. If your searches run more efficiently, they also run faster and complete sooner. Which means the system can handle more of them in the same time!&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=TkjSeSClYaQ" target="_blank"&gt;&lt;IMG alt="Identifying Slow Web Content" src="https://i.ytimg.com/vi/TkjSeSClYaQ/hqdefault.jpg" /&gt;&lt;/A&gt;&lt;/P&gt;

&lt;H1&gt;Things to know&lt;/H1&gt;

&lt;P&gt;Use the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview"&gt;Monitoring Console&lt;/A&gt; dashboards to determine if any searches have performance issues that need attention. The Monitoring Console comes with preconfigured &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Customizehealthcheck"&gt;health checks&lt;/A&gt; in addition to &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Platformalerts"&gt;platform alerts&lt;/A&gt;. You can modify existing health checks or create new ones. You can &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/SearchactivityDeploymentwide"&gt;interpret results in these dashboards&lt;/A&gt; to identify ways to optimize and troubleshoot your deployment.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/SearchactivityDeploymentwide"&gt;Search activity dashboards&lt;/A&gt;&lt;/STRONG&gt;: The &lt;STRONG&gt;Search activity: Instance&lt;/STRONG&gt; and &lt;STRONG&gt;Search activity: Deployment&lt;/STRONG&gt; dashboards show search activity across your deployment with detailed information broken down by instance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Scheduleractivity"&gt;Scheduler activity dashboards&lt;/A&gt;&lt;/STRONG&gt;: The &lt;STRONG&gt;Scheduler activity: Deployment&lt;/STRONG&gt; dashboard shows information about the past executions of scheduled searches, and their success rates. If you have a search head cluster, the &lt;STRONG&gt;Search head clustering Scheduler delegation dashboard&lt;/STRONG&gt; deals with how the &lt;A href="https://docs.splunk.com/Splexicon:Clustercaptain"&gt;captain&lt;/A&gt; orchestrates scheduler jobs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/IndexingDeployment"&gt;Indexing performance dashboards&lt;/A&gt;&lt;/STRONG&gt;: The &lt;STRONG&gt;Indexing performance: Deployment&lt;/STRONG&gt; and &lt;STRONG&gt;Indexing performance: Instance&lt;/STRONG&gt; dashboards show indexing performance across the deployment.&lt;/LI&gt;
&lt;/UL&gt;

&lt;H1&gt;Things to do&lt;/H1&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Run a health check&lt;/STRONG&gt;. &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Customizehealthcheck"&gt;Access and customize the health check&lt;/A&gt; to expose issues with source types, among other things.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Improve your source types&lt;/STRONG&gt;. Review the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Dataquality"&gt;data quality dashboards&lt;/A&gt; to identify and &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Resolvedataqualityissues"&gt;resolve data quality issues&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tune long running searches&lt;/STRONG&gt;. Review the dashboards in the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview"&gt;Monitoring Console&lt;/A&gt; to see if you notice any heavy consumers of CPU or memory usage.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Peek at pipelines&lt;/STRONG&gt;. Review the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/IndexingDeployment"&gt;indexing performance dashboards&lt;/A&gt; to identify any issues or load in a particular pipeline.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure your Splunk&lt;/STRONG&gt;. Review the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards"&gt;safeguards for risky commands&lt;/A&gt; in the &lt;EM&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/WhatyoucansecurewithSplunk"&gt;Splunk Enterprise Securing Splunk Enterprise Manual&lt;/A&gt;&lt;/EM&gt;.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 16 Sep 2019 16:04:18 GMT</pubDate>
    <dc:creator>adukes_splunk</dc:creator>
    <dc:date>2019-09-16T16:04:18Z</dc:date>
    <item>
      <title>Best practices for search optimization for Splunk Enterprise?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Enterprise/m-p/482596#M8594</link>
      <description>&lt;P&gt;Does anyone have best practices to help optimize searches for Splunk Enterprise?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 16:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Enterprise/m-p/482596#M8594</guid>
      <dc:creator>adukes_splunk</dc:creator>
      <dc:date>2019-09-16T16:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices for search optimization for Splunk Enterprise?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Enterprise/m-p/482597#M8595</link>
      <description>&lt;H2&gt;&lt;EM&gt;The Splunk Product Best Practices team provided this response. Read more about &lt;A href="https://www.splunk.com/blog/2019/02/25/how-crowdsourcing-is-shaping-the-future-of-splunk-best-practices.html"&gt;How Crowdsourcing is Shaping the Future of Splunk Best Practices&lt;/A&gt;.&lt;/EM&gt;&lt;/H2&gt;

&lt;H1&gt;Better. Stronger. Faster.&lt;/H1&gt;

&lt;P&gt;Splunk works fine out of the box. As you increase load on your system, though, you'll want to get familiar with ways to enhance its ability to handle that load. We’ll show you how to identify the cause of slow searches and review possible trouble spots in your deployment.&lt;/P&gt;

&lt;H1&gt;How search optimization helps you do more with less&lt;/H1&gt;

&lt;P&gt;Slow searches can be caused by inefficient search practices, but they can also be caused by poor data quality. You can find remarkable performance improvements when you resolve things like the incorrect event breaks and time stamp errors in the data. Inefficiencies like these can cause indexers to work overtime both when indexing data and finding the search results. If your searches run more efficiently, they also run faster and complete sooner. Which means the system can handle more of them in the same time!&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=TkjSeSClYaQ" target="_blank"&gt;&lt;IMG alt="Identifying Slow Web Content" src="https://i.ytimg.com/vi/TkjSeSClYaQ/hqdefault.jpg" /&gt;&lt;/A&gt;&lt;/P&gt;

&lt;H1&gt;Things to know&lt;/H1&gt;

&lt;P&gt;Use the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview"&gt;Monitoring Console&lt;/A&gt; dashboards to determine if any searches have performance issues that need attention. The Monitoring Console comes with preconfigured &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Customizehealthcheck"&gt;health checks&lt;/A&gt; in addition to &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Platformalerts"&gt;platform alerts&lt;/A&gt;. You can modify existing health checks or create new ones. You can &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/SearchactivityDeploymentwide"&gt;interpret results in these dashboards&lt;/A&gt; to identify ways to optimize and troubleshoot your deployment.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/SearchactivityDeploymentwide"&gt;Search activity dashboards&lt;/A&gt;&lt;/STRONG&gt;: The &lt;STRONG&gt;Search activity: Instance&lt;/STRONG&gt; and &lt;STRONG&gt;Search activity: Deployment&lt;/STRONG&gt; dashboards show search activity across your deployment with detailed information broken down by instance.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Scheduleractivity"&gt;Scheduler activity dashboards&lt;/A&gt;&lt;/STRONG&gt;: The &lt;STRONG&gt;Scheduler activity: Deployment&lt;/STRONG&gt; dashboard shows information about the past executions of scheduled searches, and their success rates. If you have a search head cluster, the &lt;STRONG&gt;Search head clustering Scheduler delegation dashboard&lt;/STRONG&gt; deals with how the &lt;A href="https://docs.splunk.com/Splexicon:Clustercaptain"&gt;captain&lt;/A&gt; orchestrates scheduler jobs.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/IndexingDeployment"&gt;Indexing performance dashboards&lt;/A&gt;&lt;/STRONG&gt;: The &lt;STRONG&gt;Indexing performance: Deployment&lt;/STRONG&gt; and &lt;STRONG&gt;Indexing performance: Instance&lt;/STRONG&gt; dashboards show indexing performance across the deployment.&lt;/LI&gt;
&lt;/UL&gt;

&lt;H1&gt;Things to do&lt;/H1&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Run a health check&lt;/STRONG&gt;. &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Customizehealthcheck"&gt;Access and customize the health check&lt;/A&gt; to expose issues with source types, among other things.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Improve your source types&lt;/STRONG&gt;. Review the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/Dataquality"&gt;data quality dashboards&lt;/A&gt; to identify and &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Resolvedataqualityissues"&gt;resolve data quality issues&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Tune long running searches&lt;/STRONG&gt;. Review the dashboards in the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/DMCoverview"&gt;Monitoring Console&lt;/A&gt; to see if you notice any heavy consumers of CPU or memory usage.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Peek at pipelines&lt;/STRONG&gt;. Review the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/DMC/IndexingDeployment"&gt;indexing performance dashboards&lt;/A&gt; to identify any issues or load in a particular pipeline.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Secure your Splunk&lt;/STRONG&gt;. Review the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/SPLsafeguards"&gt;safeguards for risky commands&lt;/A&gt; in the &lt;EM&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/WhatyoucansecurewithSplunk"&gt;Splunk Enterprise Securing Splunk Enterprise Manual&lt;/A&gt;&lt;/EM&gt;.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 16 Sep 2019 16:04:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Enterprise/m-p/482597#M8595</guid>
      <dc:creator>adukes_splunk</dc:creator>
      <dc:date>2019-09-16T16:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices for search optimization for Splunk Enterprise?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Enterprise/m-p/482598#M8596</link>
      <description>&lt;P&gt;Added related video. &lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2019 17:42:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Best-practices-for-search-optimization-for-Splunk-Enterprise/m-p/482598#M8596</guid>
      <dc:creator>adukes_splunk</dc:creator>
      <dc:date>2019-10-21T17:42:52Z</dc:date>
    </item>
  </channel>
</rss>

