All Apps and Add-ons

Any performance issues with all the real-time searches in Palo Alto Networks app?

the_wolverine
Champion

I have just installed the app and want to know if anyone has encountered any performance issues with the multitude (nearly all) real-time searches that are used in the dashboard.

I will refactor the searches to not use real-time search.

0 Karma

btorresgil
Builder

Hello. There are actually only 4 real time searches in the entire app. All of them are on the Overview Dashboard. The app uses search templates and search post process to reduce load from real-time searches, and uses datamodel acceleration in non-realtime pivots for the rest of the dashboards.

If you're experiencing performance issues, can you describe what symptoms you're seeing and how many logs per second you're sending to splunk? Is the performance problem exclusive to the Palo Alto Networks app, or across all apps? Just one dashboard, or all dashboards?

Thanks,
-Brian

0 Karma

the_wolverine
Champion

We tightly control the use of real-time searches in our env because each rt-search consumes a core of resource. Privileged users might be allowed to run a single rt-search. We have since converted all the rt searches in overview to scheduled searches.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...