Monitoring Splunk

Deployment Monitor Scalability

jonathanmorcom
Explorer

I've just done a complete re-install of this app on a new server. Only other app running on the new server is Deployment Server.

I've dropped the summary index retention to 1 month.

It still is almost un-usable... Incredibly slow load times etc. We are quite a big site, with a large amount of data so it could be related to the scale of the data it has to process from the indexers perhaps. Though it did seem to work quite a bit better on version 4.

Has anyone else had issues?

1 Solution

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

View solution in original post

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

jonathanmorcom
Explorer

I might give this a shot next week. For now have the old version happily chugging along. Thanks for the advice!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...