Monitoring Splunk

Deployment Monitor Scalability

jonathanmorcom
Explorer

I've just done a complete re-install of this app on a new server. Only other app running on the new server is Deployment Server.

I've dropped the summary index retention to 1 month.

It still is almost un-usable... Incredibly slow load times etc. We are quite a big site, with a large amount of data so it could be related to the scale of the data it has to process from the indexers perhaps. Though it did seem to work quite a bit better on version 4.

Has anyone else had issues?

1 Solution

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

View solution in original post

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

jonathanmorcom
Explorer

I might give this a shot next week. For now have the old version happily chugging along. Thanks for the advice!

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...