Monitoring Splunk

Splunk Web performance slow for VM

mcrawford44
Communicator

All,

I've noticed that web performance has been slow since installing Splunk, however I brushed it off as a hardware issue since we were on a small VM for pilot.

Once migrated to a 16vcpu server with 128gb of ram I expected performance to increase. It has not.

I've spent a couple days rummaging through configuration files and increasing CherryPy thread settings and the allocated ram for DBX, but the interface is still very slow.

Is there an optimization guide I'm missing or an obvious fix I'm missing?

Tags (2)
0 Karma

sideview
SplunkTrust
SplunkTrust

At a high level, reporting and UI slowness is more often caused by less-than-ideal disk IO, rather than CPU and ram and this goes double for VM's. Splunk reads a lot from disk and has to do it fast for reports to be fast. VM's suffer just because all else being equal they usually have less IO throughput than a physical host. Check out this what this page has to say under "Disk subsystem" http://docs.splunk.com/Documentation/Splunk/6.1.1/Installation/Referencehardware

mcrawford44
Communicator

I have just started bench-marking the disks and I believe that is the cause. Our VM OS drive is extremely low powered for some reason.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

To isolate the issue you could run a browser on the server locally and connect to itself. If that's slow then it's something on the server, if that's fast then it's something in the network.

0 Karma

mcrawford44
Communicator

I don't believe so. Tried multiple browsers across several variations of machines, from i3 laptops to i7 beasts.

I installed Splunk on my local machine and it runs as fast as expected. I'm having our network guys take a look at it.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Is it maybe your browser that's slow? You seem certain to rummage around the server, but I'd check that first.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...