Splunk Search

About real time search

yutaka1005
Builder

I want to know about CPU occupation when doing a real-time search.

If I build Splunk in a standalone way, and I configure a real-time search, I think that one of cpu core will be occupied.

But which server's cpu core is occupied by real-time search when configuring distributed search like indexer clustering?
will only cpu core of the search head be occupied? Or, because it is a distributed search, will cpu core of each search peer also be occupied?

Also, if I configured search head clustering, will cpu core of all members be occupied?

I am planning to create large scale configuration for personal use, and planning configure alerts using real time search (rolling window) in the environment, so I want to know how to use cpu core.

I appreciate if someone tell me about it.

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

In a distributed real-time search, one core for each peer is occupied, but only one core on one search head is used.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

In a distributed real-time search, one core for each peer is occupied, but only one core on one search head is used.

---
If this reply helps you, Karma would be appreciated.
0 Karma

yutaka1005
Builder

Thank you for answer.

you mean that only one core on one search head is used if search is processed in search head clustering?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, that is what I meant.

---
If this reply helps you, Karma would be appreciated.
0 Karma

yutaka1005
Builder

Thank you for answer!

I understood it!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...