Monitoring Splunk

poor performance for metrics index

giotto69
Observer

Hi everybody

we are seeing bad performances in metrics indexes searches, in particular when a "group by" clause is used on dimensions with many values

Of course performance decrease as time interval being searched increases

We set up the metric rollup mechanism to aggregate raw values into 1 hour, with the idea of having better performance. Hard to believe: search performance is worse on the aggregated index than on the original one.

it seems that the insights of how metrics indexes are built heavily impact our searches.

Does anyone have any idea, or specific info on metric indexes beyond what's written in documentation?

thanks

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...