Deployment Architecture

How can you compare performance between indexers in the same distributed indexer cluster?

myandow
Path Finder

In our existing distributed indexer cluster we have systems with slightly different configurations(storage and some slight hardware differences). I'm trying to determine if there is any difference in performance being seen by Splunk across each of these systems related to typical indexer functionality. Is there a way to measure the performance of each indexer in the existing environment for comparison?

0 Karma
1 Solution

sloshburch
Splunk Employee
Splunk Employee

https://splunkbase.splunk.com/app/3002 can show you if the system itself is performing well.

Other than that and the DMC (as mentioned by @gpradeepkumarreddy) you'll want to explore the Job Inspector to see the load per indexer and normalize with events/second: http://docs.splunk.com/Documentation/Splunk/latest/Search/ViewsearchjobpropertieswiththeJobInspector

View solution in original post

0 Karma

sloshburch
Splunk Employee
Splunk Employee

https://splunkbase.splunk.com/app/3002 can show you if the system itself is performing well.

Other than that and the DMC (as mentioned by @gpradeepkumarreddy) you'll want to explore the Job Inspector to see the load per indexer and normalize with events/second: http://docs.splunk.com/Documentation/Splunk/latest/Search/ViewsearchjobpropertieswiththeJobInspector

0 Karma

pradeepkumarg
Influencer

Start with DMC App. It has several views related to indexing performance

0 Karma

sloshburch
Splunk Employee
Splunk Employee

If you need corresponding docs for this topic: http://docs.splunk.com/Documentation/Splunk/latest/DMC/IndexingDeployment

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...