Monitoring Splunk

Is it possible for squash_threshold to increase value, and are there consequences?

AntoineDRN
Path Finder

Hello Splunkers,

I would like to have a better insight on my license usage, but the "Squash_threshold" default conf is not enough. I have been looking here if there were answers, sadly there are few answers and the rare that exist are a little old.

In the documentation, it is said to ask to a Splunk expert, my contact being in holidays yet, I would like to try to move forward anyways. 

So have you any recommendations on this setting and the possible consequences if I increase it?

 

Thanks in advance, 

Best regards,

Labels (1)

nspaitsec
New Member

Hello

On which node did they advised to set this parameter ?

on the License Manager and/or any other node ?

Thank you.

Tags (1)
0 Karma

splunkreal
Influencer

Hi @nspaitsec license manager and clustered indexers 

* If this helps, please upvote or accept solution if it solved *
0 Karma

splunkreal
Influencer

Hello, is this solved?

Support can help you.

This may increase load on your indexers.

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

AntoineDRN
Path Finder

Hello @splunkreal,

 

thanks for replying to this it was really out of my mind. 

I reached the support about it, and the conclusion was that it is possible. The best way to increase the parameter is to do it gradually and monitor the effects on the platform.

 

Regards

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...