Splunk Enterprise

Splunk Indexers sending too much of data to search heads

soumyasaha25
Contributor

my indexers are sending way too much of data to my search heads (close to 500 GBs  in a day) which is having an impact on the bandwidth utilisation. 

Although from initial investigation it seemed like some of the dashboards were running long running searches which i had killed manually, but that just helped partially, is there any other aspects that i need to look into.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Indexers should only be sending interim search results to search heads.  Do you have any indication of what is in those 500GB?

Long-running searches shouldn't be much of an issue.  One should look for searches that return a lot of data by using non-streaming commands too soon.  For instance, table in place of fields.

---
If this reply helps you, Karma would be appreciated.
0 Karma

soumyasaha25
Contributor

Thanks @richgalloway, i could not find any issues with any search in particular (yes there were users with badly written searches but that should not impact so much)  as a test i disabled the realtime metadata search that populates the search summary page (disabled it globally so that no apps have that search running) and looks like it solved the issue.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...