Deployment Architecture

Workload Management Configuration

rafeeqsid25
New Member

Currently the setup is likes this where i want to implement Workload Management ,so that the jobs need to balance all across Multisite Indexer Cluster.

Infra:-
5nos of Search Head Cluster(Each Search Head Cluster is of 6 nos Search Head Member)
Multisite Indexer Cluster(2 site each consist of 75 nos of Search Peer)

Can any one suggest me with this to how the jobs can be balance within Multisite Indexer cluster ,so that each site should not be overloaded.It will be good if is there is any sample config for workload pool configuration.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is not what Workload Management (WM) does. WM creates pools of CPU and memory resources within a system that limit what a search can use. The idea is to prevent poorly written searches from hogging resources within an indexer and affecting other activity. WM has no say in where a search executes.

You may be thinking of Search Affinity where a search head can limit its queries to a specific indexer cluster site. Load balancing among cluster sites is then a matter of distributing searches among search heads. See https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/Multisitesearchaffinity.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rafeeqsid25
New Member

Does this effect the existing setting of all Save searches after WLM Implementation,Or do i need to change the all the Save searches w.r.t to pool.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You do not need to do anything to your searches unless they run into limits imposed by WM. If that happens, modify the searches to be more efficient.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...