Deployment Architecture

Workload Management Configuration

rafeeqsid25
New Member

Currently the setup is likes this where i want to implement Workload Management ,so that the jobs need to balance all across Multisite Indexer Cluster.

Infra:-
5nos of Search Head Cluster(Each Search Head Cluster is of 6 nos Search Head Member)
Multisite Indexer Cluster(2 site each consist of 75 nos of Search Peer)

Can any one suggest me with this to how the jobs can be balance within Multisite Indexer cluster ,so that each site should not be overloaded.It will be good if is there is any sample config for workload pool configuration.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

That is not what Workload Management (WM) does. WM creates pools of CPU and memory resources within a system that limit what a search can use. The idea is to prevent poorly written searches from hogging resources within an indexer and affecting other activity. WM has no say in where a search executes.

You may be thinking of Search Affinity where a search head can limit its queries to a specific indexer cluster site. Load balancing among cluster sites is then a matter of distributing searches among search heads. See https://docs.splunk.com/Documentation/Splunk/8.0.2/Indexer/Multisitesearchaffinity.

---
If this reply helps you, Karma would be appreciated.
0 Karma

rafeeqsid25
New Member

Does this effect the existing setting of all Save searches after WLM Implementation,Or do i need to change the all the Save searches w.r.t to pool.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You do not need to do anything to your searches unless they run into limits imposed by WM. If that happens, modify the searches to be more efficient.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...