Splunk Enterprise

Splunk Indexers sending too much of data to search heads

soumyasaha25
Contributor

my indexers are sending way too much of data to my search heads (close to 500 GBs  in a day) which is having an impact on the bandwidth utilisation. 

Although from initial investigation it seemed like some of the dashboards were running long running searches which i had killed manually, but that just helped partially, is there any other aspects that i need to look into.

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Indexers should only be sending interim search results to search heads.  Do you have any indication of what is in those 500GB?

Long-running searches shouldn't be much of an issue.  One should look for searches that return a lot of data by using non-streaming commands too soon.  For instance, table in place of fields.

---
If this reply helps you, Karma would be appreciated.
0 Karma

soumyasaha25
Contributor

Thanks @richgalloway, i could not find any issues with any search in particular (yes there were users with badly written searches but that should not impact so much)  as a test i disabled the realtime metadata search that populates the search summary page (disabled it globally so that no apps have that search running) and looks like it solved the issue.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...