Monitoring Splunk

poor performance for metrics index

giotto69
Observer

Hi everybody

we are seeing bad performances in metrics indexes searches, in particular when a "group by" clause is used on dimensions with many values

Of course performance decrease as time interval being searched increases

We set up the metric rollup mechanism to aggregate raw values into 1 hour, with the idea of having better performance. Hard to believe: search performance is worse on the aggregated index than on the original one.

it seems that the insights of how metrics indexes are built heavily impact our searches.

Does anyone have any idea, or specific info on metric indexes beyond what's written in documentation?

thanks

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...