Monitoring Splunk

Is it possible for squash_threshold to increase value, and are there consequences?

AntoineDRN
Path Finder

Hello Splunkers,

I would like to have a better insight on my license usage, but the "Squash_threshold" default conf is not enough. I have been looking here if there were answers, sadly there are few answers and the rare that exist are a little old.

In the documentation, it is said to ask to a Splunk expert, my contact being in holidays yet, I would like to try to move forward anyways. 

So have you any recommendations on this setting and the possible consequences if I increase it?

 

Thanks in advance, 

Best regards,

Labels (1)

splunkreal
Motivator

Hello, is this solved?

Support can help you.

This may increase load on your indexers.

 

* If this helps, please upvote or accept solution 🙂 *
0 Karma

AntoineDRN
Path Finder

Hello @splunkreal,

 

thanks for replying to this it was really out of my mind. 

I reached the support about it, and the conclusion was that it is possible. The best way to increase the parameter is to do it gradually and monitor the effects on the platform.

 

Regards

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...