Deployment Architecture

How can you compare performance between indexers in the same distributed indexer cluster?

myandow
Path Finder

In our existing distributed indexer cluster we have systems with slightly different configurations(storage and some slight hardware differences). I'm trying to determine if there is any difference in performance being seen by Splunk across each of these systems related to typical indexer functionality. Is there a way to measure the performance of each indexer in the existing environment for comparison?

0 Karma
1 Solution

sloshburch
Ultra Champion

https://splunkbase.splunk.com/app/3002 can show you if the system itself is performing well.

Other than that and the DMC (as mentioned by @gpradeepkumarreddy) you'll want to explore the Job Inspector to see the load per indexer and normalize with events/second: http://docs.splunk.com/Documentation/Splunk/latest/Search/ViewsearchjobpropertieswiththeJobInspector

View solution in original post

0 Karma

sloshburch
Ultra Champion

https://splunkbase.splunk.com/app/3002 can show you if the system itself is performing well.

Other than that and the DMC (as mentioned by @gpradeepkumarreddy) you'll want to explore the Job Inspector to see the load per indexer and normalize with events/second: http://docs.splunk.com/Documentation/Splunk/latest/Search/ViewsearchjobpropertieswiththeJobInspector

0 Karma

pradeepkumarg
Influencer

Start with DMC App. It has several views related to indexing performance

0 Karma

sloshburch
Ultra Champion

If you need corresponding docs for this topic: http://docs.splunk.com/Documentation/Splunk/latest/DMC/IndexingDeployment

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...