Splunk Enterprise

Splunk Indexers sending too much of data to search heads

soumyasaha25
Contributor

my indexers are sending way too much of data to my search heads (close to 500 GBs  in a day) which is having an impact on the bandwidth utilisation. 

Although from initial investigation it seemed like some of the dashboards were running long running searches which i had killed manually, but that just helped partially, is there any other aspects that i need to look into.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Indexers should only be sending interim search results to search heads.  Do you have any indication of what is in those 500GB?

Long-running searches shouldn't be much of an issue.  One should look for searches that return a lot of data by using non-streaming commands too soon.  For instance, table in place of fields.

---
If this reply helps you, Karma would be appreciated.
0 Karma

soumyasaha25
Contributor

Thanks @richgalloway, i could not find any issues with any search in particular (yes there were users with badly written searches but that should not impact so much)  as a test i disabled the realtime metadata search that populates the search summary page (disabled it globally so that no apps have that search running) and looks like it solved the issue.

0 Karma
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...