Using Splunk enterprise 9.0.41. Users are reporting most page transitions between apps and dashboards are taking several seconds (10 +). Even logging on with the search app as my default app takes 30 seconds+. There does not appear to be any CPU/memory pinch on our single search head as we monitor this with telegraf. Looking into MS Edge dev tools I see pattern like this
It's not browser or user specific. It also happens from the server itself if we use the browser over an RDP session so not network latency from end user browser to search head either
Where could I start to look for clues as to why this is occurring?
Hi
is this in virtual or physical environment and which OS and version? Do you have sinle node or distributed environment? What you health indicator shows? How much data you are ingesting? Are there anything interesting in MC?
r. Ismo
Ingest ~ 15 GB per day. We have
All Windows Server 2019 and basic metrics of CPU Usage, CPU queue, memory/Swapping and Disk latency and negligible. It seems to have started when we recently upgrade from 8 to 9 and gotten worse. The monitoring console shows no issues.
Those should be more than enough for your current load.
You have done all regularly needed Windows OS cleaning tasks or are those “just running”? You have checked that there haven’t installed any windows updates at “same” time than you update splunk?
If these don’t help, I try to look 1st that OS side is ok and after that create support case to splunk.