Monitoring Splunk

What are the measures to check Splunk performance issue.

nishu3788
Explorer

Hi Splunkers,

Good Day!

We have a multisite distributive environment in which we are experiencing performance issue like slowness while running Splunk reports, dashboards and ad-hoc searches in later half of the day, while it is running good in first half. We are looking to use Splunk as 24x7 but its like the first 12hrs it is running good but next 12hrs the performance gets degraded and gets worse.

Can you someone please tell what are the things/performance measures I can check in order to find the issue. One of the reason I believe is regular patching of servers during that hour. How can I investigate something from Splunk end?

Thanks in advance.

Tags (1)
0 Karma

DalJeanis
Legend

Per George, an expert on Splunk multisite deployments at Rational Cyber, "It seems like their WAN is saturated by replication. They should look at queue fullness and at tcp out connections for replication."

0 Karma

CarsonZa
Contributor

Have you checked the DMC? There is lots of good info in there. Personally I would check search activity first.

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...