<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Indexer Tuning Best Practices: How to decide which apps or add-ons are not needed? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Tuning-Best-Practices-How-to-decide-which-apps-or-add/m-p/273796#M52508</link>
    <description>&lt;P&gt;I want to clean up the indexers and remove unnecessary Apps that could be using up unnecessary CPU and memory. I have three indexers and they all have a different set of apps on each of the three indexers. I am on Splunk version 6.2.3&lt;/P&gt;

&lt;P&gt;How can I tell if an app is needed on the indexer?&lt;BR /&gt;
For instance the Windows app is on only one indexer.&lt;BR /&gt;
Do I need this on all three or none?&lt;BR /&gt;
I also have S.o.S - Splunk on Splunk on all three indexers, one has the TA-splunk and the Splunk app/add-on for *nix.&lt;BR /&gt;
Are all three TA-s needed? Don't they all run scripted inputs?&lt;BR /&gt;
Is there some where or some one that has addressed indexer tuning best practices?&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2016 13:14:59 GMT</pubDate>
    <dc:creator>hartfoml</dc:creator>
    <dc:date>2016-04-04T13:14:59Z</dc:date>
    <item>
      <title>Indexer Tuning Best Practices: How to decide which apps or add-ons are not needed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Tuning-Best-Practices-How-to-decide-which-apps-or-add/m-p/273796#M52508</link>
      <description>&lt;P&gt;I want to clean up the indexers and remove unnecessary Apps that could be using up unnecessary CPU and memory. I have three indexers and they all have a different set of apps on each of the three indexers. I am on Splunk version 6.2.3&lt;/P&gt;

&lt;P&gt;How can I tell if an app is needed on the indexer?&lt;BR /&gt;
For instance the Windows app is on only one indexer.&lt;BR /&gt;
Do I need this on all three or none?&lt;BR /&gt;
I also have S.o.S - Splunk on Splunk on all three indexers, one has the TA-splunk and the Splunk app/add-on for *nix.&lt;BR /&gt;
Are all three TA-s needed? Don't they all run scripted inputs?&lt;BR /&gt;
Is there some where or some one that has addressed indexer tuning best practices?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 13:14:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Tuning-Best-Practices-How-to-decide-which-apps-or-add/m-p/273796#M52508</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2016-04-04T13:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer Tuning Best Practices: How to decide which apps or add-ons are not needed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-Tuning-Best-Practices-How-to-decide-which-apps-or-add/m-p/273797#M52509</link>
      <description>&lt;P&gt;There are a few things you should do:&lt;/P&gt;

&lt;P&gt;How can I tell if an app is needed on the indexer?&lt;BR /&gt;
 - Generally you can find out if the documentation for the app says it has index-time operations.  You'll have to examine each app and see if there are any transforms or props stanzas that would apply at index-time.&lt;/P&gt;

&lt;P&gt;Specifically, the windows app contains entries in props.conf that modify sourcetype, which is an index-time operation.  So you'll need it on the indexers.  You only need it on the indexers where you're sending the windows logs, which is probably all of them.&lt;/P&gt;

&lt;P&gt;For the SoS app I'm not sure what the requirements are, but you probably need them all running on all of the indexers to collect information from them.&lt;/P&gt;

&lt;P&gt;You might consider setting up a "heavy forwarder" layer where all of your apps are installed, and then removing all or most of the apps from the indexers.  That way the tasks of index-time operations can all be done on the heavy forwarders instead of the indexers.&lt;/P&gt;

&lt;P&gt;You might find this useful as well: &lt;A href="http://wiki.splunk.com/Things_I_wish_I_knew_then"&gt;http://wiki.splunk.com/Things_I_wish_I_knew_then&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 04:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-Tuning-Best-Practices-How-to-decide-which-apps-or-add/m-p/273797#M52509</guid>
      <dc:creator>niemesrw</dc:creator>
      <dc:date>2016-04-05T04:25:17Z</dc:date>
    </item>
  </channel>
</rss>

