Monitoring Splunk

Splunk Web performance slow for VM

mcrawford44
Communicator

All,

I've noticed that web performance has been slow since installing Splunk, however I brushed it off as a hardware issue since we were on a small VM for pilot.

Once migrated to a 16vcpu server with 128gb of ram I expected performance to increase. It has not.

I've spent a couple days rummaging through configuration files and increasing CherryPy thread settings and the allocated ram for DBX, but the interface is still very slow.

Is there an optimization guide I'm missing or an obvious fix I'm missing?

Tags (2)
0 Karma

sideview
SplunkTrust
SplunkTrust

At a high level, reporting and UI slowness is more often caused by less-than-ideal disk IO, rather than CPU and ram and this goes double for VM's. Splunk reads a lot from disk and has to do it fast for reports to be fast. VM's suffer just because all else being equal they usually have less IO throughput than a physical host. Check out this what this page has to say under "Disk subsystem" http://docs.splunk.com/Documentation/Splunk/6.1.1/Installation/Referencehardware

mcrawford44
Communicator

I have just started bench-marking the disks and I believe that is the cause. Our VM OS drive is extremely low powered for some reason.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

To isolate the issue you could run a browser on the server locally and connect to itself. If that's slow then it's something on the server, if that's fast then it's something in the network.

0 Karma

mcrawford44
Communicator

I don't believe so. Tried multiple browsers across several variations of machines, from i3 laptops to i7 beasts.

I installed Splunk on my local machine and it runs as fast as expected. I'm having our network guys take a look at it.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Is it maybe your browser that's slow? You seem certain to rummage around the server, but I'd check that first.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...