Reporting

Setting Workload Categories for Workload Management

sanjay_e
Engager

How do you determine how much CPU and memory to allocate to Search, Index, and Miscellaneous?

0 Karma
1 Solution

splunk_zen
Builder

I've used the Monitoring Console to gain familiarity with the median and max resource consumption trends for the indexers and Search Heads and set it according to that.

Miscellaneous are scripted/modular inputs so you only need to cover those on your Heavy Forwarders

Above all, remember to set generous headroom and remember the beauty of Workload Categories is this doesn't have to be written in stone and you can change them later with ease.
Let me know if you have a more specific question about WLM

View solution in original post

splunk_zen
Builder

I've used the Monitoring Console to gain familiarity with the median and max resource consumption trends for the indexers and Search Heads and set it according to that.

Miscellaneous are scripted/modular inputs so you only need to cover those on your Heavy Forwarders

Above all, remember to set generous headroom and remember the beauty of Workload Categories is this doesn't have to be written in stone and you can change them later with ease.
Let me know if you have a more specific question about WLM

sanjay_e
Engager

Hi splunk_zen,

Thank you for your reply - Do the indexers map directly to ingest and the search heads directly to search? From my understanding, indexers aid when running searches as well, so I thought that it may be inaccurate to set the categories based just on the resource consumption of search heads/indexers.

Also, do you know why the default split is 70:20:10 for search:index:miscellaneous? When I checked the resource consumption, indexers used far more resources than search heads so I wanted to double-check that this approach was fine.

And one last question! Does workload management kick in once we activate it? ie. Should I expect search heads and indexers to go down if they don't have enough resources immediately after we install it?

0 Karma

splunk_zen
Builder

First of all, did you already setup linux cgroups?
Your understanding of indexers is correct, but please spin this into a new question to keep things clearer for everyone

0 Karma

sandeepmakkena
Contributor
0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...