Deployment Architecture

My searchhead is slow since I update from 6 to 7.2.3

Alaza
Explorer

Hello,

since I update my Splunk search head from 6 to 7.2.3, the display of the dashboards are very slow.
In fact, all the action are slowed than the anterior version.
But my index are the same and the upgrade has been done with no error.

Any clues about that ?

Regards,
Alaza

0 Karma
1 Solution

nickhills
Ultra Champion

Many of the 7.2.x versions had a number of memory and CPU implications (trust me - I think we found each and every one)
7.2.4 addresses all of the tickets and bugs we had open, and so far it does appear to be significantly better than 7.2.3.

If my comment helps, please give it a thumbs up!

View solution in original post

nickhills
Ultra Champion

Many of the 7.2.x versions had a number of memory and CPU implications (trust me - I think we found each and every one)
7.2.4 addresses all of the tickets and bugs we had open, and so far it does appear to be significantly better than 7.2.3.

If my comment helps, please give it a thumbs up!

marios_kstone
Path Finder

I have a similar issue after upgrading from 6.6.0 to 7.2.1. We noticed the slowness is present in searches with a lot of append operations. In some cases searches that previously took few seconds, now take 10+ minutes.
Analyzing search.log we pinpointed the issue to be on the search optimization. Disabling search optimizatiion appending | noop search_optimization=false to the query partially solves the problem (the search is slower than before, but at least acceptable).

0 Karma

p_gurav
Champion

Which was previous splunk version, 6.0?

0 Karma

aecruzp
Path Finder

In my case from 6.6.11 to 7.2.3

0 Karma

Alaza
Explorer

It was the 6.6.3.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...