In our environment we have Splunk HF with 2 parallel Ingestion Pipelines.
One of the aim of those Splunk HF is to offload the Splunk Indexer on parsing Pipeline, Merging Pipeline and Typing Pipeline. Due to that the data coming from Splunk HF are already "processed" and our Indexer are mostly processing them only in the Index Pipeline.
On the Indexers we only have 1 Ingestion Pipeline, the CPU Cores used for indexing are typically 4-6.
Does our Indexers are taking advantage using pretty much all the 4-6 CPU Cores for the Index Pipeline only OR they are "wasted" on the other mostly idle pipelines?
Thanks a lot,