How to find thrput of data being searched in Splunk?


We are planning to for a F5 load-balancer to be placed in front of the search heads. For sizing, how can I find out the following:
1. Current throughput for searches
2. Max thrput
3. Number of user sessions

The management console (which aggregates data from the whole distributed environment) shows data for the indexers, index, sourcetypes but no the user activity. Is there any query to find out the above?

Thank you in advance.

Tags (3)
0 Karma

Ultra Champion

You could install the stream forwarder on your searchheads and profile your current usage over a few days.

0 Karma


Since it is production it cannot be done.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!