Archive

How to find thrput of data being searched in Splunk?

Communicator

We are planning to for a F5 load-balancer to be placed in front of the search heads. For sizing, how can I find out the following:
1. Current throughput for searches
2. Max thrput
3. Number of user sessions

The management console (which aggregates data from the whole distributed environment) shows data for the indexers, index, sourcetypes but no the user activity. Is there any query to find out the above?

Thank you in advance.

Tags (3)
0 Karma

Ultra Champion

You could install the stream forwarder on your searchheads and profile your current usage over a few days.

0 Karma

Communicator

Since it is production it cannot be done.

0 Karma