- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk resource usage by users/searches
Hi all,
We are seeing a scenario where there are a lot of unoptimised searches, dashboards etc which when run are exhausting our CPU on indexers. If some users run resource intensive adhoc searches/dashboards etc simultaneously, this is becoming a problem as so many searches running together resulting in 'server busy' error at indexer.
1. Is there any way we can throttle CPU/memory usage per user/role/searches?
2. Are there any documents on optimising searches for better performance and less resource usage?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


1. Check out the Workload Management feature. https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/Admin/WorkloadManagement
2. That's about as much art as it is science. The Search Manual has a chapter on it that should get you started. https://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutoptimization
If this reply helps you, Karma would be appreciated.
