Splunk Enterprise

Very Slow User Interface

shocko
Contributor

Using Splunk enterprise 9.0.41. Users are reporting most page transitions between apps and dashboards are taking several seconds (10 +). Even logging on with the search app as my default app takes 30 seconds+. There does not appear to be any CPU/memory pinch on our single search head as we monitor this with telegraf. Looking into MS Edge dev tools I see pattern like this

shocko_1-1688659351428.png

It's not browser or user specific.  It also happens from the server itself if we use the browser over an RDP session so not network latency from end user browser to search head either

Where could I start to look for clues as to why this is occurring? 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

is this in virtual or physical environment and which OS and version? Do you have sinle node or distributed environment? What you health indicator shows? How much data you are ingesting? Are there anything interesting in MC?

r. Ismo

Tags (1)

shocko
Contributor

Ingest ~ 15 GB per day. We have

  1. One search head (32 cores and 64 GB RAM) [Physical]
  2. One cluster master (4 Cores and 32 GB RAM) [VM]
  3. 2 indexers (32 Cores and 64 GB  RAM) [Physical]

All Windows Server 2019 and basic metrics of CPU Usage, CPU queue, memory/Swapping and Disk latency and negligible. It seems to have started when we recently upgrade from 8 to 9 and gotten worse. The monitoring console shows no issues. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Those should be more than enough for your current load. 
You have done all regularly needed Windows OS cleaning tasks or are those “just running”? You have checked that there haven’t installed any windows updates at “same” time than you update splunk?

If these don’t help, I try to look 1st that OS side is ok and after that create support case to splunk.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...