Monitoring Splunk

about splunk improve performance

khyoung7410
Communicator

Hi

Specifically Is there a way to improve performance?


Two of the indexer and search my splunk configuration header is one.


My splunk configuration is Two indexer and One search header.


Thank you

  • my hardware capa

    Raid = 1+0

    MEM = 16GB

    CPU = Intel Xeon 2 Quardcore 2.4GHz

    Day Volume = 100GB

Tags (1)
0 Karma

Ayn
Legend

What does bonnie++ say about disk performance?

0 Karma

Drainy
Champion

Are you currently experiencing performance problems? If so where is the bottleneck, is it with searching or indexing?
Also how many users are accessing the platform and how many searches are you running?

At a first look I would say another indexer wouldn't hurt, Splunk scales horizontally very well and adding additional indexers improves search performance due to mapReduce and also through reducing the IO load on the other indexers. Search heads are useful to add if you have larger numbers of users logging on and firing off searches but in this instance I would probably say an extra indexer (or two) but then as per my first comments, there are a lot of other factors 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...