Deployment Architecture

Where do I configure parallelization settings in an indexer clustering environment?

ontkanin
Path Finder

Hi there,

I am trying to configure my Splunk environment (1xSH, 2xIndexers (cluster), 1xClusterMaster) to use parallelization, as described in Parallelization settings.

While I understand that parallelIngestionPipelines should be configured on indexers, I am kind of not very sure where the batch_search_max_pipeline settings should be configured.

  • on Indexers?
  • on Search Head?
  • on Indexers and Search Head?

The documentation is not very clear on that, or I'm not getting it.

Thank you

0 Karma
1 Solution

sk314
Builder

From the docs at http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/Configurebatchmodesearch#Configure_batch...

You can enable and configure batch mode search parallelization with an additional set of limits.conf parameters. This is an indexer-side setting. It needs to be configured on all of your indexers, not your search head(s).

View solution in original post

sk314
Builder

From the docs at http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/Configurebatchmodesearch#Configure_batch...

You can enable and configure batch mode search parallelization with an additional set of limits.conf parameters. This is an indexer-side setting. It needs to be configured on all of your indexers, not your search head(s).

ontkanin
Path Finder

Thanks a lot sk314. I must have been blind for not seeing that sentence. I really appreciate your help.

0 Karma

sk314
Builder

You are welcome. To be fair, It's a couple of links down the chain...

Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...