<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Performance Issues in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94366#M1148</link>
    <description>&lt;P&gt;The splunk server is acting as a search head as well as an indexer.&lt;/P&gt;

&lt;P&gt;The specifications of the server is as follows:&lt;/P&gt;

&lt;P&gt;DL 380 G5 14Gb RAM 1 x Quad Intel Xeon 2Ghz processor&lt;/P&gt;

&lt;P&gt;There is a dashboard configured which would have 36 traffic lights. Behind these traffic lights there are saved searches for each traffic light which at different intervals. The dashboard is set to refresh every 10 minutes. The total amount of scheduled searches are roughly 30.&lt;/P&gt;

&lt;P&gt;Normally the dashboard is open up on three Pc's.If i look at the cpu on the splunk server it can be normally running is at 100%.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2011 11:22:51 GMT</pubDate>
    <dc:creator>itsomana</dc:creator>
    <dc:date>2011-10-25T11:22:51Z</dc:date>
    <item>
      <title>Splunk Performance Issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94364#M1146</link>
      <description>&lt;P&gt;Our Splunk server is constantly running at 98% cpu and the performance in splunk switching between different screens is terrible.  I have a number of saved searches and reports which are linked to a traffic light dashboard.  Is there any way I can determine is killing the splunk server? &lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2011 13:31:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94364#M1146</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-10-19T13:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Performance Issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94365#M1147</link>
      <description>&lt;P&gt;More info would help:&lt;/P&gt;

&lt;P&gt;What are the hardware spec's for you server ?  &lt;/P&gt;

&lt;P&gt;Should we assume that this box is serving as a search-head as well as an indexer ? &lt;/P&gt;

&lt;P&gt;How many scheduled searches do you have ?&lt;/P&gt;

&lt;P&gt;Have you made any edit to your limits.conf ?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2011 18:58:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94365#M1147</guid>
      <dc:creator>JSapienza</dc:creator>
      <dc:date>2011-10-19T18:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Performance Issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94366#M1148</link>
      <description>&lt;P&gt;The splunk server is acting as a search head as well as an indexer.&lt;/P&gt;

&lt;P&gt;The specifications of the server is as follows:&lt;/P&gt;

&lt;P&gt;DL 380 G5 14Gb RAM 1 x Quad Intel Xeon 2Ghz processor&lt;/P&gt;

&lt;P&gt;There is a dashboard configured which would have 36 traffic lights. Behind these traffic lights there are saved searches for each traffic light which at different intervals. The dashboard is set to refresh every 10 minutes. The total amount of scheduled searches are roughly 30.&lt;/P&gt;

&lt;P&gt;Normally the dashboard is open up on three Pc's.If i look at the cpu on the splunk server it can be normally running is at 100%.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2011 11:22:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94366#M1148</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-10-25T11:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Performance Issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94367#M1149</link>
      <description>&lt;P&gt;There is a limit.conf file that will slow down your system becasue you have too many saved searches per CPU.  You could change the limit but that is risky and could cause even more issues.  Personally I would work with Splunk Professional services to maximize your saved searches and dashboard to fit your hardware or increase your hardware to fit your needs.  if you were to increase your hardware you would need more than 10 CPU cores. Check out the hardware planning links below for more help.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/installation/SystemRequirements"&gt;http://docs.splunk.com/Documentation/Splunk/latest/installation/SystemRequirements&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Installation/CapacityplanningforalargerSplunkdeployment"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Installation/CapacityplanningforalargerSplunkdeployment&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;CPU &lt;BR /&gt;
Allow 1 CPU core for every 1MB/s of indexing volume &lt;BR /&gt;
Allow 1 CPU core for Splunk's optimization routines for every 2MB/s of indexing volume &lt;BR /&gt;
Allow 1 CPU per active searcher (be sure to account for scheduled searches) &lt;/P&gt;

&lt;P&gt;"The Splunk server will start to queue searches if the number of concurrent searches is greater than 4 * (numberOfCores + 1)"&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/82/i-keep-getting-this-max-concurrent-searches-reached-error-what-does-it-mean-and-how-do-i-fix-it"&gt;http://splunk-base.splunk.com/answers/82/i-keep-getting-this-max-concurrent-searches-reached-error-what-does-it-mean-and-how-do-i-fix-it&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2011 14:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94367#M1149</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-10-25T14:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Performance Issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94368#M1150</link>
      <description>&lt;P&gt;hartfoml, many thanks for your reply.   Could I just confirm one thing around saved searches and reports.  If I have 60 saved searches and reports, however as I said 30 are scheduled to run at different intervals and the other 30 have a time range set to run at different intervals also, I assume that the latter 30 saved scheduled jobs will also impede performance?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2011 14:57:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94368#M1150</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-10-25T14:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Performance Issues</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94369#M1151</link>
      <description>&lt;P&gt;The performance hit of "4 * (numberOfCores + 1)" is for concurrent searches but as you have three people that have a browser open and the searches running in the background I can’t say what is causing the issue.  If you can monitor the Splund service either in top or in windows “perfmon” to find out if this is the cause of you high CPU use or is there another service that may be contributing.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2011 15:52:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Performance-Issues/m-p/94369#M1151</guid>
      <dc:creator>hartfoml</dc:creator>
      <dc:date>2011-10-25T15:52:41Z</dc:date>
    </item>
  </channel>
</rss>

