Deployment Architecture

Load on indexers high, am I able to add more indexers to help?

KulvinderSingh
Path Finder

hi all,

I have 3 indexers with 26 CPU/ indexer they are crying out loud due to load. 

I may not be able to increase CPU's as such there is a limit and max is 26 cores. Will adding more indexers help?

 

Labels (1)
0 Karma
1 Solution

PickleRick
SplunkTrust
SplunkTrust

There is no single good answer.

Everything depends on what's really going on in your environment.

Remember that different forms of search (dense, sparse...) might have different requirements. Some are more IO-heavy and less reliant on CPU, others might work on cached data so don't read much from disks but will happily eat your CPUs.

So it all depends on your workload characteristics.

In general - Splunk should be pretty horizontally scalable and often it's better to add more indexers than to pump up existing ones. Especially if IO is the bottleneck.

But it would be best if you engaged your local Splunk partner to assess the situation and recommend a proper solution.

And of course remember that there is always the possibility that you can simply reorganize some searches, optimize dashboards and you might get away without touching existing infrastructure.

View solution in original post

PickleRick
SplunkTrust
SplunkTrust

There is no single good answer.

Everything depends on what's really going on in your environment.

Remember that different forms of search (dense, sparse...) might have different requirements. Some are more IO-heavy and less reliant on CPU, others might work on cached data so don't read much from disks but will happily eat your CPUs.

So it all depends on your workload characteristics.

In general - Splunk should be pretty horizontally scalable and often it's better to add more indexers than to pump up existing ones. Especially if IO is the bottleneck.

But it would be best if you engaged your local Splunk partner to assess the situation and recommend a proper solution.

And of course remember that there is always the possibility that you can simply reorganize some searches, optimize dashboards and you might get away without touching existing infrastructure.

gcusello
SplunkTrust
SplunkTrust

Hi @KulvinderSingh,

if you cannot increase CPUs you can always scalate your infrastrutture adding one or more Indexers.

Only one hint: see, using the Monitoring Console, why you have a so high CPU use, maybethere's something wrong in utilization.

E.g.: if you're using many Real time searches that can be converted in scheduled searches or you can use accelerated Data Models or other ways to have quicker searches.

Using Monitoring Console, you can see the active searches and what happens when there's a peak.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...