Deployment Architecture

Where do I configure parallelization settings in an indexer clustering environment?

ontkanin
Path Finder

Hi there,

I am trying to configure my Splunk environment (1xSH, 2xIndexers (cluster), 1xClusterMaster) to use parallelization, as described in Parallelization settings.

While I understand that parallelIngestionPipelines should be configured on indexers, I am kind of not very sure where the batch_search_max_pipeline settings should be configured.

  • on Indexers?
  • on Search Head?
  • on Indexers and Search Head?

The documentation is not very clear on that, or I'm not getting it.

Thank you

0 Karma
1 Solution

sk314
Builder

From the docs at http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/Configurebatchmodesearch#Configure_batch...

You can enable and configure batch mode search parallelization with an additional set of limits.conf parameters. This is an indexer-side setting. It needs to be configured on all of your indexers, not your search head(s).

View solution in original post

sk314
Builder

From the docs at http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/Configurebatchmodesearch#Configure_batch...

You can enable and configure batch mode search parallelization with an additional set of limits.conf parameters. This is an indexer-side setting. It needs to be configured on all of your indexers, not your search head(s).

ontkanin
Path Finder

Thanks a lot sk314. I must have been blind for not seeing that sentence. I really appreciate your help.

0 Karma

sk314
Builder

You are welcome. To be fair, It's a couple of links down the chain...

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...