Splunk Search

Export scheduled saved search processing to another server

rbw78
Communicator

Hello,

Currently we're processing about 30 scheduled saved search in our splunk server.
The processing of these searches are taking a lot of ressources in CPU and memory.

So i was wondering if there's a way to export the processing functions to another server making our splunk server less overloaded ?
The goal would be to use the splunk server to just ensure the display of the searches on the dashboards.

Thanks

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

it'a called a dedicated search-head, and you can setup your scheduled searches on it.
The difficulty is to separate them properly and avoid to have them run twice.
http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Installadedicatedsearchhead

If you want to see the results on your other search-head, you can save the results in a summary index (and forward it to the indexers). That way your dashboards will show preprocessed results (much faster).

Have you tried splunk 5.0, it has search improvement for statistical results.

Keep in mind that ultimately the searches will run on the indexers too.

View solution in original post

0 Karma

yannK
Splunk Employee
Splunk Employee

it'a called a dedicated search-head, and you can setup your scheduled searches on it.
The difficulty is to separate them properly and avoid to have them run twice.
http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Installadedicatedsearchhead

If you want to see the results on your other search-head, you can save the results in a summary index (and forward it to the indexers). That way your dashboards will show preprocessed results (much faster).

Have you tried splunk 5.0, it has search improvement for statistical results.

Keep in mind that ultimately the searches will run on the indexers too.

0 Karma

rbw78
Communicator

Great, thanks for the answer I hadn't seen this feature in the documentation that exactly what i was looking for.

0 Karma

yannK
Splunk Employee
Splunk Employee

I forgot to mention the search-head pooling (using a shared folder between the search-heads). Any available search-head will run the search, and the results will be available from both in the shared dispatch folders.

It has some high requirements to run properly, so test well before.
http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configuresearchheadpooling

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...