<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practices When Dealing with Real Time Searches In Dashboards in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Best-Practices-When-Dealing-with-Real-Time-Searches-In/m-p/154771#M43513</link>
    <description>&lt;P&gt;1 and 3 are the same. Each real-time search consumes 1 CPU core. You can add them as saved searches, and call the saved searches using the  tags in your dashboard, rather than an in-line search. That should solve the problem you described, where multiple instances of the dashboard are consuming all of the CPU.&lt;/P&gt;

&lt;P&gt;Honestly, best practice is to not use real-time. If you can schedule the searches to run on 1 minute intervals, it's far better utilization of resources.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2015 22:02:11 GMT</pubDate>
    <dc:creator>masonmorales</dc:creator>
    <dc:date>2015-04-22T22:02:11Z</dc:date>
    <item>
      <title>Best Practices When Dealing with Real Time Searches In Dashboards</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Best-Practices-When-Dealing-with-Real-Time-Searches-In/m-p/154770#M43512</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;This is sorta opened ended. Since I am not too familiar with Real time searches short of just running a quick search. &lt;/P&gt;

&lt;P&gt;I have about 40 users, who will on and off want to use a dashboard which is using 3 real time searches. Once more than 4-5 users are using Splunk sorta grinds to a halt. How can I get them to share the same output, rather than running their searches separately? &lt;/P&gt;

&lt;P&gt;Any other best practices I should be aware of? &lt;BR /&gt;
1) Resource estimating&lt;BR /&gt;
2) Setting time limits? &lt;BR /&gt;
3) Real time searches and searches/per cpu impact? &lt;BR /&gt;
4) ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2015 21:47:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Best-Practices-When-Dealing-with-Real-Time-Searches-In/m-p/154770#M43512</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2015-04-22T21:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices When Dealing with Real Time Searches In Dashboards</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Best-Practices-When-Dealing-with-Real-Time-Searches-In/m-p/154771#M43513</link>
      <description>&lt;P&gt;1 and 3 are the same. Each real-time search consumes 1 CPU core. You can add them as saved searches, and call the saved searches using the  tags in your dashboard, rather than an in-line search. That should solve the problem you described, where multiple instances of the dashboard are consuming all of the CPU.&lt;/P&gt;

&lt;P&gt;Honestly, best practice is to not use real-time. If you can schedule the searches to run on 1 minute intervals, it's far better utilization of resources.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2015 22:02:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Best-Practices-When-Dealing-with-Real-Time-Searches-In/m-p/154771#M43513</guid>
      <dc:creator>masonmorales</dc:creator>
      <dc:date>2015-04-22T22:02:11Z</dc:date>
    </item>
  </channel>
</rss>

