Getting Data In

Will the increase of logging to metrics.log impact performance on an indexer?

ben_leung
Builder

I want to have a bigger picture on sourcetypes/indexes in the metrics.log. The default "series" shown in metrics is 10..

[metrics]

maxseries = <integer>
* The number of series to include in the per_x_thruput reports in metrics.log.
* Defaults to 10.

If there is over 500 source types, it would make sense to set the maxseries value in limits.conf to accommodate for all the series/sourcetypes that will log information in the metrics.log

My concern is that if this number is very high, there will be more resources allocated to the logging of metrics.log. How can we measure the impact if it is set to 500? Will there be any impact?

0 Karma

masonmorales
Influencer

Try it in a test environment first.

0 Karma

ben_leung
Builder

How will I judge if there is an impact in performance? Just by running a search to see if it took longer to load? Is there a way to measure the difference? Even if it is a small change?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...