<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Summary Indexing and Performance in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Summary-Indexing-and-Performance/m-p/126554#M7470</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;You're on the rigth way but you forgoted something or/and you make some mistakes.&lt;/P&gt;

&lt;P&gt;Summary indexes are there to accelerate the results of searches but it's not the only thing.&lt;BR /&gt;
You must know that the first condition to respect so that the performance of your dashboards can be improved is that each of your dashboards most not have more than 8 searches. This condition is essential for splunk to displays and runs correctly your dashboards.&lt;/P&gt;

&lt;P&gt;So before using Summary indexes, make sure that your dashboards respect that condition.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2015 10:43:36 GMT</pubDate>
    <dc:creator>NOUMSSI</dc:creator>
    <dc:date>2015-03-18T10:43:36Z</dc:date>
    <item>
      <title>Summary Indexing and Performance</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Summary-Indexing-and-Performance/m-p/126553#M7469</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;So i have been looking for ways to improve performance of my dashboards - to give you summary - i currently have 3 Dashboards and each dashboard is running more than 50 Searches at a given time, all the dashboards are hosted on 1 Search head which is feed by 2 indexers for data.&lt;/P&gt;

&lt;P&gt;i have been reading and seems like Summary Indexing along with Schedule search is solution i am looking but i have few doubts and would greatly appreciate if some on can chime in 2 cents based on past experience:&lt;BR /&gt;
 1. I am planning to create 150 Scheduled Searches (none of them is duplicate) to run every 15 Minutes ( i want to run them every 15 minutes because - we need real time dashboard)&lt;BR /&gt;
 2. I will then put output of these schedule searches in different summary indexes (because of different people need access to different data)&lt;BR /&gt;
 3. Then run my Advanced XML dashboards against these Summary index saved results. &lt;/P&gt;

&lt;P&gt;Questions i have:&lt;BR /&gt;
 1. Is this right move? or is there is anything better which can help improve  dashboard performance. (at any given time we can have up-to 20 people logged in and looking at real time dashboards).&lt;BR /&gt;
 2. One thing i noted is that Summary Indexes get data from Scheduled Searches which atleast 1 Hour behind in time, why is it so? if my Adv XML is running a search against Summary Index then that means i can never get data which is near real time ? i do not want to wait for 1 hr before data for now shows up on dashboard - am i missing something?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 23:19:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Summary-Indexing-and-Performance/m-p/126553#M7469</guid>
      <dc:creator>nikhilmehra79</dc:creator>
      <dc:date>2014-04-09T23:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Indexing and Performance</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Summary-Indexing-and-Performance/m-p/126554#M7470</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;You're on the rigth way but you forgoted something or/and you make some mistakes.&lt;/P&gt;

&lt;P&gt;Summary indexes are there to accelerate the results of searches but it's not the only thing.&lt;BR /&gt;
You must know that the first condition to respect so that the performance of your dashboards can be improved is that each of your dashboards most not have more than 8 searches. This condition is essential for splunk to displays and runs correctly your dashboards.&lt;/P&gt;

&lt;P&gt;So before using Summary indexes, make sure that your dashboards respect that condition.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 10:43:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Summary-Indexing-and-Performance/m-p/126554#M7470</guid>
      <dc:creator>NOUMSSI</dc:creator>
      <dc:date>2015-03-18T10:43:36Z</dc:date>
    </item>
  </channel>
</rss>

