Reporting

Is it known that disabled saved searches cause poor performance?

bsizemore
Path Finder

Hello, one of our engineers through trial and error discovered something that has been hobbling our Splunkfrastructure for months. We had 300 saved searches on one of our servers, 150 of which were disabled. He deleted all 150 disabled saved searches, and now our platform’s performance is orders of magnitude greater. Is this well known?

Tags (2)
1 Solution

bsizemore
Path Finder

Well, this was our experience.

View solution in original post

0 Karma

bsizemore
Path Finder

Well, this was our experience.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

No skipped searches that I know of, rather sluggish UX... I'll check that nonetheless.

bsizemore
Path Finder

If you have piles of disabled saved searches, and you have numerous skipped searches, as we had, maybe you can try it an let us know how that works out. We are on 6.0.3.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Ah... I wasn't thinking of a solution, just wondering if I should try this on some SHP environment that has become a bit sluggish lately 🙂

bsizemore
Path Finder

The host in question is an isolated job server. We do use pooling of search heads, which this host is not a member of.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Are you using Search Head Pooling?

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...