Monitoring Splunk

Where does the burden fall on a search?

mjj47
New Member

I have an enterprise system composed of 6 search heads and 8 indexers. I am trying to look at current cpu loads to tell how well my current system is set up. When I issue a search, which machine is doing the heavy lifting? indexers, or search head? I'm just curious as to how splunk does searching. Thanks.

Tags (2)
0 Karma

grijhwani
Motivator

The search head merely aggregates and formats for presentation the results it gets back from distributed queries to the indexers. The indexers do all the hard work of index searching and collating, which is heavy on IO, and moderately heavy on CPU. Search head load is pretty trivial in comparison.

Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...