Hi all,
We are seeing a scenario where there are a lot of unoptimised searches, dashboards etc which when run are exhausting our CPU on indexers. If some users run resource intensive adhoc searches/dashboards etc simultaneously, this is becoming a problem as so many searches running together resulting in 'server busy' error at indexer.
1. Is there any way we can throttle CPU/memory usage per user/role/searches?
2. Are there any documents on optimising searches for better performance and less resource usage?
1. Check out the Workload Management feature. https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/Admin/WorkloadManagement
2. That's about as much art as it is science. The Search Manual has a chapter on it that should get you started. https://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutoptimization