hi all,
I have 3 indexers with 26 CPU/ indexer they are crying out loud due to load.
I may not be able to increase CPU's as such there is a limit and max is 26 cores. Will adding more indexers help?
There is no single good answer.
Everything depends on what's really going on in your environment.
Remember that different forms of search (dense, sparse...) might have different requirements. Some are more IO-heavy and less reliant on CPU, others might work on cached data so don't read much from disks but will happily eat your CPUs.
So it all depends on your workload characteristics.
In general - Splunk should be pretty horizontally scalable and often it's better to add more indexers than to pump up existing ones. Especially if IO is the bottleneck.
But it would be best if you engaged your local Splunk partner to assess the situation and recommend a proper solution.
And of course remember that there is always the possibility that you can simply reorganize some searches, optimize dashboards and you might get away without touching existing infrastructure.
There is no single good answer.
Everything depends on what's really going on in your environment.
Remember that different forms of search (dense, sparse...) might have different requirements. Some are more IO-heavy and less reliant on CPU, others might work on cached data so don't read much from disks but will happily eat your CPUs.
So it all depends on your workload characteristics.
In general - Splunk should be pretty horizontally scalable and often it's better to add more indexers than to pump up existing ones. Especially if IO is the bottleneck.
But it would be best if you engaged your local Splunk partner to assess the situation and recommend a proper solution.
And of course remember that there is always the possibility that you can simply reorganize some searches, optimize dashboards and you might get away without touching existing infrastructure.
Hi @KulvinderSingh,
if you cannot increase CPUs you can always scalate your infrastrutture adding one or more Indexers.
Only one hint: see, using the Monitoring Console, why you have a so high CPU use, maybethere's something wrong in utilization.
E.g.: if you're using many Real time searches that can be converted in scheduled searches or you can use accelerated Data Models or other ways to have quicker searches.
Using Monitoring Console, you can see the active searches and what happens when there's a peak.
Ciao.
Giuseppe