Deployment Architecture

Load on indexers high, am I able to add more indexers to help?

KulvinderSingh
Path Finder

hi all,

I have 3 indexers with 26 CPU/ indexer they are crying out loud due to load. 

I may not be able to increase CPU's as such there is a limit and max is 26 cores. Will adding more indexers help?

 

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

There is no single good answer.

Everything depends on what's really going on in your environment.

Remember that different forms of search (dense, sparse...) might have different requirements. Some are more IO-heavy and less reliant on CPU, others might work on cached data so don't read much from disks but will happily eat your CPUs.

So it all depends on your workload characteristics.

In general - Splunk should be pretty horizontally scalable and often it's better to add more indexers than to pump up existing ones. Especially if IO is the bottleneck.

But it would be best if you engaged your local Splunk partner to assess the situation and recommend a proper solution.

And of course remember that there is always the possibility that you can simply reorganize some searches, optimize dashboards and you might get away without touching existing infrastructure.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

There is no single good answer.

Everything depends on what's really going on in your environment.

Remember that different forms of search (dense, sparse...) might have different requirements. Some are more IO-heavy and less reliant on CPU, others might work on cached data so don't read much from disks but will happily eat your CPUs.

So it all depends on your workload characteristics.

In general - Splunk should be pretty horizontally scalable and often it's better to add more indexers than to pump up existing ones. Especially if IO is the bottleneck.

But it would be best if you engaged your local Splunk partner to assess the situation and recommend a proper solution.

And of course remember that there is always the possibility that you can simply reorganize some searches, optimize dashboards and you might get away without touching existing infrastructure.

gcusello
SplunkTrust
SplunkTrust

Hi @KulvinderSingh,

if you cannot increase CPUs you can always scalate your infrastrutture adding one or more Indexers.

Only one hint: see, using the Monitoring Console, why you have a so high CPU use, maybethere's something wrong in utilization.

E.g.: if you're using many Real time searches that can be converted in scheduled searches or you can use accelerated Data Models or other ways to have quicker searches.

Using Monitoring Console, you can see the active searches and what happens when there's a peak.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...