All Apps and Add-ons

Splunk Enterprise Security slow performance

splunky_diamond
Path Finder

Hello splunkers!

Has anyone else experienced slow performance with Splunk Enterprise Security? For me, when I open the "Content Management" in  "Configure" and let's say try to filter to see enabled correlation searches, it might take up to 5 minutes to load just 5 or 6 correlation searches. However, if I try to perform a search in search and reporting (Within Enterprise Security) the searches will run pretty much fast, returning hunderds of thousands of events. Another case where I might experience huge lags is when: creating a new investigation, updating the status of the notable, deleting investigation, opening Incident review settings, adding new note in investigation.

If anyone had similar experience could someone please share how to improve the performance in Enterprise Security app?

Some notes to give more info about my case:
- The health circle is green. 
- The deployment is all-in-one (Splunk Enterprise, ES, and all the apps and add-ons, everything is running on ubuntu server 20.04 virtual machine with 42 GB RAM, 200 GB hard disk (thin provisioned), 32 vCPU
- My Splunk deployment has around 4-5 sources from which it receives the logs, average load of data is around 500-700 MB/day

Thanks for taking your time reading  and replying to my post ❤️

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunky_diamond,

which ES version did you installed?

this was a known bug solved with ES 7.3.

Ciao.

Giuseppe

0 Karma

splunky_diamond
Path Finder

Hello @gcusello ,

See below I show the .spl file name and download date.

splunky_diamond_0-1716436775675.png

 

I believe I have the latest version of the ES currently.

Cheers,

splunky_diamond

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @splunky_diamond,

yes it's the latest!

open a case to Splunk Support, as I said this is an old resolved bug.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...