Reporting

Pivot loading splunk excessively ?

agneticdk
Path Finder

Hi

In the example in 6.0 on the audit log: Splunk's Internal Audit Logs - SAMPLE and looking on the pivot of "Audit" - Under the menu "Audit" in top right corner there is the Acceleration, Earliest and Started.

Earliest is when the splunk installation was done, because the data model is over "All time" (no earliest parameter defined). So thats a long way back. And now I can see the accelereation just chews away.

If I make my own data model without earliest paramter it will always take "All time" I guess.

I have to be very careful on my pivot datamodels, because if I create a few datamodels and grant access to those for lets say 10 people, when they start clicking around in the Pivot menus these acceleration searches will run for each user, on each table or chart ? Resulting in my search head and indexers doing a lot of work, as it will continue running until either the search times out or finishes on "All time", for each user ?

One way to limit this is to grant users only access to a limited timeframe, or by adding "earliest" to my datamodel.

Any comments ?

Tags (3)
1 Solution

Simon_Fishel
Splunk Employee
Splunk Employee

The acceleration searches should run only once for each user's session in the pivot interface, they do not need to be re-run for each table and chart that is created. And they should expire soon after each user stops using the pivot interface. I wouldn't expect the load on the search head to be much different than from 10 users running searches over all time in the search interface.

Another way to limit the load would be to accelerate the data model. Then all users of pivot are actually sharing the results of a single acceleration search.

View solution in original post

Simon_Fishel
Splunk Employee
Splunk Employee

The acceleration searches should run only once for each user's session in the pivot interface, they do not need to be re-run for each table and chart that is created. And they should expire soon after each user stops using the pivot interface. I wouldn't expect the load on the search head to be much different than from 10 users running searches over all time in the search interface.

Another way to limit the load would be to accelerate the data model. Then all users of pivot are actually sharing the results of a single acceleration search.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...