Monitoring Splunk

poor performance for metrics index

giotto69
Observer

Hi everybody

we are seeing bad performances in metrics indexes searches, in particular when a "group by" clause is used on dimensions with many values

Of course performance decrease as time interval being searched increases

We set up the metric rollup mechanism to aggregate raw values into 1 hour, with the idea of having better performance. Hard to believe: search performance is worse on the aggregated index than on the original one.

it seems that the insights of how metrics indexes are built heavily impact our searches.

Does anyone have any idea, or specific info on metric indexes beyond what's written in documentation?

thanks

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...