Getting Data In

Is it possible to check sed performance in props.conf?

sc0tt
Builder

Is there a way to test the performance of sed scripts running in props.conf? I'm not an expert in regular expressions so I want to make sure that I'm not creating bottlenecks when indexing events. Events are < 1000 characters.

Thanks.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

You can see sed- and regex-related load during indexing by grabbing the SoS app from http://apps.splunk.com/app/748/ and opening the Indexing Performance view. A screen or two down you'll see index load by processes, you're looking for the regexprocessor.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

You can see sed- and regex-related load during indexing by grabbing the SoS app from http://apps.splunk.com/app/748/ and opening the Indexing Performance view. A screen or two down you'll see index load by processes, you're looking for the regexprocessor.

martin_mueller
SplunkTrust
SplunkTrust

Just install the app, it's free and has literally hundreds of other benefits.

If for some reason you seriously cannot install it you can download it, unpack, and grab the search behind the graph manually. It's basically extracting information from the _internal index, so you can run the query without the app.

0 Karma

sc0tt
Builder

Great info! Is there an example of creating this report with without installing the app?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...