Monitoring Splunk

Deployment Monitor Scalability

jonathanmorcom
Explorer

I've just done a complete re-install of this app on a new server. Only other app running on the new server is Deployment Server.

I've dropped the summary index retention to 1 month.

It still is almost un-usable... Incredibly slow load times etc. We are quite a big site, with a large amount of data so it could be related to the scale of the data it has to process from the indexers perhaps. Though it did seem to work quite a bit better on version 4.

Has anyone else had issues?

1 Solution

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

View solution in original post

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

jonathanmorcom
Explorer

I might give this a shot next week. For now have the old version happily chugging along. Thanks for the advice!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...