Getting Data In

Will the increase of logging to metrics.log impact performance on an indexer?

ben_leung
Builder

I want to have a bigger picture on sourcetypes/indexes in the metrics.log. The default "series" shown in metrics is 10..

[metrics]

maxseries = <integer>
* The number of series to include in the per_x_thruput reports in metrics.log.
* Defaults to 10.

If there is over 500 source types, it would make sense to set the maxseries value in limits.conf to accommodate for all the series/sourcetypes that will log information in the metrics.log

My concern is that if this number is very high, there will be more resources allocated to the logging of metrics.log. How can we measure the impact if it is set to 500? Will there be any impact?

0 Karma

masonmorales
Influencer

Try it in a test environment first.

0 Karma

ben_leung
Builder

How will I judge if there is an impact in performance? Just by running a search to see if it took longer to load? Is there a way to measure the difference? Even if it is a small change?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...