I am trying to configure my Splunk environment (1xSH, 2xIndexers (cluster), 1xClusterMaster) to use parallelization, as described in Parallelization settings.
While I understand that
parallelIngestionPipelines should be configured on indexers, I am kind of not very sure where the
batch_search_max_pipeline settings should be configured.
The documentation is not very clear on that, or I'm not getting it.
You can enable and configure batch mode search parallelization with an additional set of limits.conf parameters. This is an indexer-side setting. It needs to be configured on all of your indexers, not your search head(s).
Thanks a lot sk314. I must have been blind for not seeing that sentence. I really appreciate your help.