Getting Data In

indexThreads is set to auto how many threads does that mean?

DrewO
Splunk Employee
Splunk Employee

How can I tell how many threads have been allocated using the auto tune setting of indexThreads?

--snip from indexs.conf.spec --

indexThreads = <number or "auto">
* Specifying "auto" or an invalid value will cause Splunk to autotune this param based on your system
* The number of threads to use for indexing
* The number has to be at least 1 and at most 16
* If specified as < 0 or more than 16, it will be autotuned
* This number should not be set higher than the number of processors in the box.
* If splunkd is also doing parsing and aggregation, the number should be lower than the total number of processors minus two.
* Please only set this value if you are an expert user or are advised by Splunk Support
* CARELESSNESS IN SETTING THIS MAY LEAD TO PERMANENT BRAIN DAMAGE OR LOSS OF JOB
Tags (2)
0 Karma

mkelderm
Path Finder

This is my qeuery 4.3.4:

index="_internal" source=*splunkd.log indexProcessor AND indexThreads AND param AND autotuned

marc

0 Karma

zscgeek
Path Finder

Splunkd.log will tell you what the auto selected value is:

Do a splunk search for "index="_internal" indexThreads param autotuned"

you will get back a result that looks like this:

splunkd.log.1:07-27-2010 21:51:49.747 INFO  IndexProcessor - indexes.conf - indexThreads param autotuned to 2

AS for the laser equipped rhino the best I can do right now is this:

laser shark

DrewO
Splunk Employee
Splunk Employee

Ha! I tried that answer . . . they wanted MORE!

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I want a pet rhinoceros with laser eye-beams and a razor-sharpened steel horn.

gkanapathy
Splunk Employee
Splunk Employee

I guess:

  • You can't.
  • Why would you need to know?

Leave it on auto and forget about it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...