Getting Data In

Will the increase of logging to metrics.log impact performance on an indexer?

ben_leung
Builder

I want to have a bigger picture on sourcetypes/indexes in the metrics.log. The default "series" shown in metrics is 10..

[metrics]

maxseries = <integer>
* The number of series to include in the per_x_thruput reports in metrics.log.
* Defaults to 10.

If there is over 500 source types, it would make sense to set the maxseries value in limits.conf to accommodate for all the series/sourcetypes that will log information in the metrics.log

My concern is that if this number is very high, there will be more resources allocated to the logging of metrics.log. How can we measure the impact if it is set to 500? Will there be any impact?

0 Karma

masonmorales
Influencer

Try it in a test environment first.

0 Karma

ben_leung
Builder

How will I judge if there is an impact in performance? Just by running a search to see if it took longer to load? Is there a way to measure the difference? Even if it is a small change?

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...