Deployment Architecture

[Performance] What does exactly an indexer and a search head during a search ?

olivier_ma
Explorer

Hello,

I currently meet some performance issue during my search (for instance, one of my search takes 75 hours with multiple sub-search for correlation). So I'm looking for some performance improvement.

That's why I try to find the exact task allocation between an indexer and a search head when we run a search on Splunk.
Let's take an example that can help you to explain me :
index=a field_1=b | eval field_2=lower(field_1) | lookup l_1 field_2 OUTPUT field_3

Also inline fields extraction is done on indexer side or search head ?

Thanks,

Tags (1)
0 Karma

jensonthottian
Contributor

I think a summary index would be a good idea to retrieve results faster.
http://docs.splunk.com/Documentation/Splunk/6.0.2/Knowledge/Usesummaryindexing

This should help you.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...