Hi Guys,
I have a very basic question.I designed a dashboard it extracts data from Oracle database , now client is asking me to deploy it(I mean they are asking me to provide them a link for this dashboard) so that different users can access it.
My question/doubt here is how many users can access this dashboard.Do we have any parameters which can suggest like for 10gb splunk licensed version these much users can access/hit a single dashboard or any documentation for the same.Why I am asking this because I am aware that I can create unlimited users in Splunk but there must be a threshold that after this it'll impact speed..
Please suggest
Hi Vikas, if you schedule all the underlying searches then users will not be required to actually run the searches. The dashboard will load the results from a previously scheduled run of those searches and you will not hit any search concurrency issues.
Hi Vikas, if you schedule all the underlying searches then users will not be required to actually run the searches. The dashboard will load the results from a previously scheduled run of those searches and you will not hit any search concurrency issues.
Thanks @linu1988. I get it Thanks allot....
This means if you can schedule the search and use the history in the dashbaord rather than user triggering the searches again and again. The savedsearch will not trigger new jobs for the same data hence avoiding searches/concurrent search issue.
If the user needs the live data then the above will not be useful.
Search of Dashboard examples with savedsearches you will get plenty of results.
@the_wolverine thanks for the advice but could you please elaborate it further .I mean what do you mean by Underlying searches ?
Hello Vikas,
There is no threshold to your dashboard user access or the amount of license you have. The issue may happen with the resource being consumed by all the users and the availability of the CPU for those searches. So it depends how many users are performing the searches concurrently. Their searches will be put to queue as per their role's limitation and the number of cores you have in your server.
Thanks
there are not many documents specific to your need. May be you use the autorize.conf file to restrict users. Take a look at this answer, will help
_http://answers.splunk.com/answers/113134/how-to-set-up-a-limit-to-max-no-of-events-to-be-searched
@linu1988 Thanks for the reply, do we have any document for this from where I can get some idea??
It depends the power you have in your server and the role you make for the users to request the searches. If you can control or manage them efficiently you can figure out whats the limit!
@linu1988 thanks for the quick response, all the users will be having the same role .They are allowed to open the dashboard only and yes you are right problem occurs if users are performing the searches concurrently.I guess I should start creating users and should stop when it creates problem...