Getting Data In

How to monitor multiple data pipelines?

splunk_force_as
Path Finder

I'm planning to introduce index parallelization into our Splunk deployment given the additional resources we have on our indexers. In looking at the DMC, specifically under Indexing Performance, I don't see that it accounts for multiple data pipelines running in parallel. What is the best way to monitor multiple data pipelines running on one indexer.

0 Karma
1 Solution

a212830
Champion

You need the DMC - Indexing Performance - Instance. It will show the pipelines for that instance, and you can then select individual ones.

alt text

View solution in original post

splunk_force_as
Path Finder

This also works: | rest splunk_server= ENTER HOST /services/server/introspection/queues

0 Karma

a212830
Champion

You need the DMC - Indexing Performance - Instance. It will show the pipelines for that instance, and you can then select individual ones.

alt text

splunk_force_as
Path Finder

Thanks for the comment. I do not see that when there are two or three Data Pipelines running in parallel.

"the pipelinesets setting in server.conf. When pipeline sets are used (that is, if pipelinesets is set to a value greater than 1), some panels in the DMC indexing performance dashboards will be blank." Is there a work around?

0 Karma

MuS
Legend

@a212830 is right, you can see it there. I just uploaded a screenshot where you can see the Parallel Data Pipelines. Did you check they are enabled and do you run DMC on the correct instance? This was take running a stand alone instance.

cheers, MuS

0 Karma

splunk_force_as
Path Finder

Thanks @MuS

0 Karma

splunk_force_as
Path Finder

It's the version. Looks like Parallel Data Pipelines are shown on the DMC for version 6.4.X. We are running version 6.3.2.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...