Getting Data In

How to index and use unstructured huge volume of data - Splunk HWF and SH cluster?

jincy_18
Path Finder

Hi All,

We are working on a clustered environment where splunk is fetching logs from various servers. In the source server we have set up splunk heavy weight forwarder which forwards the data to the load balanced HWF then to indexers.
Now the issue we face is that our logs are in nested json/ unstructured format and is of huge volume. This is making the searches too slow and crash.
We have tried index time extractions but that is also slower due to the volume.
Could you please suggest a work around for this.

TIA

0 Karma

vliggio
Communicator

What do you mean "huge volumes"? How large are your json objects (ie, how many characters per object, and how many levels deep are the objects), and are you sure that they are fully compliant json objects?

Why do you have heavy weight forwarders on your source server, another load balanced HWF layer, and then indexers? What do you mean "index time extractions but that is also slower due to the volume"? Are you saying the search is slower?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...