<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Realtime Search backfilling and slowdown in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170834#M48928</link>
    <description>&lt;P&gt;Real-time searches cause an delay in the indexers because of the way the fit into the indexers queues. Basically, real-time searches make the events available for searching before they hit the disk (the indexing queues).&lt;/P&gt;

&lt;P&gt;Splunk 6.0 introduces "&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Search/Realtimeperformanceandlimitations#Indexed_real-time_searches"&gt;indexed real-time&lt;/A&gt;" which functions mostly the same but is dramatically easier on your indexers. I have been using it and I prefer it.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2013 04:33:17 GMT</pubDate>
    <dc:creator>LukeMurphey</dc:creator>
    <dc:date>2013-12-09T04:33:17Z</dc:date>
    <item>
      <title>Realtime Search backfilling and slowdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170831#M48925</link>
      <description>&lt;P&gt;So i am trying to find the bottleneck in our hardware layout as i am running into a lot of slowdown in realtime searches. They can sometime backfill for 2-3 minutes as i dont think my indexers can keep up with the data and search usage. My hardware layout is as follows:&lt;/P&gt;

&lt;P&gt;5 dedicated search heads with 8 cores and 12 gig of ram&lt;BR /&gt;
8 dedicated indexers with 32 cores and 16 gb of memory&lt;/P&gt;

&lt;P&gt;150-200 GB of data usage per day&lt;/P&gt;

&lt;P&gt;20-25 realtime (5 minute) searches running 24/7&lt;BR /&gt;
an additional 5-10 users searching data 24/7 as well&lt;/P&gt;

&lt;P&gt;From what i have poked around on here and found. It looks like my indexers cant keep up with the IO's of all the realtime searches and logging the information at the same time.&lt;/P&gt;

&lt;P&gt;Any idea's?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2013 19:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170831#M48925</guid>
      <dc:creator>jmheaton</dc:creator>
      <dc:date>2013-12-08T19:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Realtime Search backfilling and slowdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170832#M48926</link>
      <description>&lt;P&gt;I do the following to make realtime searches perform. This does result in a bit of a delay -- which is ok for most the my needs.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Rather than realtime, create scheduled searches that run once per minute and aggregate the data of a single minute (usually -2m@m to -1m@m, in order to allow sufficient indexing time -- you may need more or less depending on indexing latency) using stats or sistats, and save the results of these scheduled searches into a summary index.&lt;/LI&gt;
&lt;LI&gt;Create a saved search that references the summary indexes rather than the raw logs.&lt;/LI&gt;
&lt;LI&gt;Run the saved searches as realtime searches.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 08 Dec 2013 21:46:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170832#M48926</guid>
      <dc:creator>joebensimo</dc:creator>
      <dc:date>2013-12-08T21:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Realtime Search backfilling and slowdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170833#M48927</link>
      <description>&lt;P&gt;Giving it a shot, we'll see how it goes.&lt;BR /&gt;
Also going to run some at -6m ending -1m.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Dec 2013 22:31:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170833#M48927</guid>
      <dc:creator>jmheaton</dc:creator>
      <dc:date>2013-12-08T22:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Realtime Search backfilling and slowdown</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170834#M48928</link>
      <description>&lt;P&gt;Real-time searches cause an delay in the indexers because of the way the fit into the indexers queues. Basically, real-time searches make the events available for searching before they hit the disk (the indexing queues).&lt;/P&gt;

&lt;P&gt;Splunk 6.0 introduces "&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Search/Realtimeperformanceandlimitations#Indexed_real-time_searches"&gt;indexed real-time&lt;/A&gt;" which functions mostly the same but is dramatically easier on your indexers. I have been using it and I prefer it.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2013 04:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Realtime-Search-backfilling-and-slowdown/m-p/170834#M48928</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2013-12-09T04:33:17Z</dc:date>
    </item>
  </channel>
</rss>

