Monitoring Splunk

Benchmarking search: indexer vs search head.

Michael_Wilde
Splunk Employee
Splunk Employee

I've just setup a search head that will search across 2 load balanced indexers.  I'd like to compare the execution time of equivalent searches

 

1) when run on the new search head

2) when run our "old way" on the indexers themselves.

  Is there something I could use that tells me how long the search takes to execute?  Something maybe like the Splunk equivalent of the "time" command on Unix/Linux?

gkanapathy
Splunk Employee
Splunk Employee

You can use the "inspect search" dialog which is available from the flashtimeline view "Actions" menu. If you pull the search results from the "jobs" page, it should pop into the flashtimeline view (usually) and you should be able to get to the menu item from there.

You can of course also use the unix time command with CLI searches.

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...