Especially when alot of collegues have our dashboard opened we get a lot of delayed searches, and our deployment becomes terribbly slow! We have quite a beefy machine but it still seems to eat all of it's CPU. Is there any search finetuning we can do to get a quicker deployment?
Hi @jeronssk,
at first, you have to monitor the performances of your infrastructure using the Monitoring Console App.
Using it you could find that your infrastructure isn't correctly designed for the requirements (especially number of users and concurrent searches.
In addition, I hint to measure the performances of your storage system because usually it is the bottleneck of each architecture: remember that Splunk requires at least 800 IOPS (better 1200) for the storage.
You can check this using tools like Bonnie++.
Anyway, you can makes different intervenes, that I hint to perform all:
About the first point:
About the second point:
About the third point:
I hope to give you some hint to approach the problem, but, as I said, this is a job for a specialist (Architects or PS).
Ciao.
Giuseppe
Hi @jeronssk,
at first, you have to monitor the performances of your infrastructure using the Monitoring Console App.
Using it you could find that your infrastructure isn't correctly designed for the requirements (especially number of users and concurrent searches.
In addition, I hint to measure the performances of your storage system because usually it is the bottleneck of each architecture: remember that Splunk requires at least 800 IOPS (better 1200) for the storage.
You can check this using tools like Bonnie++.
Anyway, you can makes different intervenes, that I hint to perform all:
About the first point:
About the second point:
About the third point:
I hope to give you some hint to approach the problem, but, as I said, this is a job for a specialist (Architects or PS).
Ciao.
Giuseppe