Splunk IT Service Intelligence

Fine tuning Splunk services and base search.

vardhanp
New Member

Hi Team,

We are using Splunk ITSI and we are planning to improve Splunk performance, we need help in understanding how much overhead each service gives on Splunk server,
So to understand this in a better way please read the scenario below

We have one platform say "App" where we have 5 servers and we need to measure performance on the basis of 3 KPI's i.e CPU Utilization, Memory Utilization & Disk Utilization, Now to measure the performance of the overall platform we need to measure the performance of each host.

So here we have two service configuration methods.

First :
1: We will create base search for the KPI's
2: We will create one service for each host having its host as an entity all 3 KPI's in it.
3: Then create one overall service for the "App" platform having Service dependencies in it where we will mention services created for all 5 hosts.

Second :
1: We will create base search for the KPI's
2: We will create one overall service for the "App" platform having its all 5 host as an entity all 3 KPI's in it.

So i want to understand here which method will more efficient and give less overhead on splunk.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...