Getting Data In

How to monitor multiple data pipelines?

splunk_force_as
Path Finder

I'm planning to introduce index parallelization into our Splunk deployment given the additional resources we have on our indexers. In looking at the DMC, specifically under Indexing Performance, I don't see that it accounts for multiple data pipelines running in parallel. What is the best way to monitor multiple data pipelines running on one indexer.

0 Karma
1 Solution

a212830
Champion

You need the DMC - Indexing Performance - Instance. It will show the pipelines for that instance, and you can then select individual ones.

alt text

View solution in original post

splunk_force_as
Path Finder

This also works: | rest splunk_server= ENTER HOST /services/server/introspection/queues

0 Karma

a212830
Champion

You need the DMC - Indexing Performance - Instance. It will show the pipelines for that instance, and you can then select individual ones.

alt text

splunk_force_as
Path Finder

Thanks for the comment. I do not see that when there are two or three Data Pipelines running in parallel.

"the pipelinesets setting in server.conf. When pipeline sets are used (that is, if pipelinesets is set to a value greater than 1), some panels in the DMC indexing performance dashboards will be blank." Is there a work around?

0 Karma

MuS
Legend

@a212830 is right, you can see it there. I just uploaded a screenshot where you can see the Parallel Data Pipelines. Did you check they are enabled and do you run DMC on the correct instance? This was take running a stand alone instance.

cheers, MuS

0 Karma

splunk_force_as
Path Finder

Thanks @MuS

0 Karma

splunk_force_as
Path Finder

It's the version. Looks like Parallel Data Pipelines are shown on the DMC for version 6.4.X. We are running version 6.3.2.

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, August edition

In the dynamic world of cybersecurity, staying ahead means constantly solving new puzzles and optimizing your ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Whether you're managing complex deployments or looking to future-proof your data infrastructure, this session ...