Splunk Enterprise

Splunk Indexers sending too much of data to search heads

soumyasaha25
Contributor

my indexers are sending way too much of data to my search heads (close to 500 GBs  in a day) which is having an impact on the bandwidth utilisation. 

Although from initial investigation it seemed like some of the dashboards were running long running searches which i had killed manually, but that just helped partially, is there any other aspects that i need to look into.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Indexers should only be sending interim search results to search heads.  Do you have any indication of what is in those 500GB?

Long-running searches shouldn't be much of an issue.  One should look for searches that return a lot of data by using non-streaming commands too soon.  For instance, table in place of fields.

---
If this reply helps you, Karma would be appreciated.
0 Karma

soumyasaha25
Contributor

Thanks @richgalloway, i could not find any issues with any search in particular (yes there were users with badly written searches but that should not impact so much)  as a test i disabled the realtime metadata search that populates the search summary page (disabled it globally so that no apps have that search running) and looks like it solved the issue.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...