Monitoring Splunk

Benchmarking search: indexer vs search head.

Michael_Wilde
Splunk Employee
Splunk Employee

I've just setup a search head that will search across 2 load balanced indexers.  I'd like to compare the execution time of equivalent searches

 

1) when run on the new search head

2) when run our "old way" on the indexers themselves.

  Is there something I could use that tells me how long the search takes to execute?  Something maybe like the Splunk equivalent of the "time" command on Unix/Linux?

gkanapathy
Splunk Employee
Splunk Employee

You can use the "inspect search" dialog which is available from the flashtimeline view "Actions" menu. If you pull the search results from the "jobs" page, it should pop into the flashtimeline view (usually) and you should be able to get to the menu item from there.

You can of course also use the unix time command with CLI searches.

Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...