Monitoring Splunk

Deployment Monitor Scalability

jonathanmorcom
Explorer

I've just done a complete re-install of this app on a new server. Only other app running on the new server is Deployment Server.

I've dropped the summary index retention to 1 month.

It still is almost un-usable... Incredibly slow load times etc. We are quite a big site, with a large amount of data so it could be related to the scale of the data it has to process from the indexers perhaps. Though it did seem to work quite a bit better on version 4.

Has anyone else had issues?

1 Solution

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

View solution in original post

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

jonathanmorcom
Explorer

I might give this a shot next week. For now have the old version happily chugging along. Thanks for the advice!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...