<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: slow splunk seaches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523161#M147557</link>
    <description>&lt;P&gt;8 apps&lt;/P&gt;</description>
    <pubDate>Tue, 06 Oct 2020 11:29:16 GMT</pubDate>
    <dc:creator>gauravmsharma</dc:creator>
    <dc:date>2020-10-06T11:29:16Z</dc:date>
    <item>
      <title>slow splunk seaches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523149#M147554</link>
      <description>&lt;P&gt;A simple search(index="xx"&amp;nbsp;source="/aa/bb/cc.log") made on my searchead takes 4 minutes to display 7.5 millon events for past 4 hours. This seems to be a very slow performance. My architecture contains 2 peer nodes and a master plus searchead which are dedicated machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;More complex searches with regex takes enormous time. Where do i start troubleshooting this slowness.&lt;/P&gt;&lt;P&gt;Does inceasing IOPS for hot db (/var/opt/splunk/db) on my peer nodes, will have a postive effect on my perfomance or any other things to check on this.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 10:27:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523149#M147554</guid>
      <dc:creator>gauravmsharma</dc:creator>
      <dc:date>2020-10-06T10:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: slow splunk seaches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523151#M147555</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214482"&gt;@gauravmsharma&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;iops improvement is good.. also, generally improving search speed is a complex task, requires lot of analysis...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://conf.splunk.com/files/2017/slides/speed-up-your-searches.pdf" target="_blank" rel="noopener"&gt;https://conf.splunk.com/files/2017/slides/speed-up-your-searches.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/Writebettersearches" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/Writebettersearches&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/Quicktipsforoptimization" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Search/Quicktipsforoptimization&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the summary indexing, data model acceleration ideas will improve search performance good.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(PS - i have given around 500+ karma points so far, received badge for that, if an answer helped you, a karma point would be nice!. we all should start "Learn, Give Back, Have Fun")&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 10:35:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523151#M147555</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-06T10:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: slow splunk seaches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523158#M147556</link>
      <description>&lt;P&gt;How many diff apps do you have installed on your search head?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 11:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523158#M147556</guid>
      <dc:creator>leonard_dupray</dc:creator>
      <dc:date>2020-10-06T11:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: slow splunk seaches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523161#M147557</link>
      <description>&lt;P&gt;8 apps&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 11:29:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/slow-splunk-seaches/m-p/523161#M147557</guid>
      <dc:creator>gauravmsharma</dc:creator>
      <dc:date>2020-10-06T11:29:16Z</dc:date>
    </item>
  </channel>
</rss>

