Splunk Search

How many concurrent searches are possible in Splunk Cloud?

LWilliamson1
Explorer

Hello,

I am considering migrating an environment to Splunk Cloud. How many concurrent searches are possible in the packages? I want to stay on the 5GB indexed, but I am concerned the concurrent searches may not be enough.

0 Karma

bandit
Motivator

https://docs.splunk.com/Documentation/SplunkCloud/latest/Service/SplunkCloudservice#Splunk_Cloud_ser...

I believe this implies that Splunk Cloud is running on a 32 core host(max_searches_per_cpu) + 6(base_max_searches) searches coming to a total of 38 concurrent searches per search head. You may also be eligible for a search cluster in Splunk Cloud at volumes of 1TB/day and higher (Check with your sales rep). Once on a search cluster which requires a minimum of 3 nodes, you should be able to run 3 x (38) or a total of 114 concurrent searches.

By default Splunk cloud max_searches_perc will only let the scheduler use up to half of the 38 searches (19). You may be able to adjust that percentage upward if have fewer adhoc search users and wish to give the scheduler the ability to run more concurrent searches or lower the value to leave more adhoc searches for users.

max_searches_perc = <integer>
* The maximum number of searches the scheduler can run, as a percentage of the
  maximum number of concurrent searches, see [search] max_searches_per_cpu for
  how to set the system wide maximum number of searches.
* Default: 50
0 Karma

amiracle
Splunk Employee
Splunk Employee

Splunk Cloud offers 38 concurrent searches per the documentation: https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/Service/SplunkCloudservice and look under "Splunk Cloud service limits and constraints"

Please note, that this is a service and the concurrent search load might change with newer versions of the Splunk Cloud service offering.

0 Karma

gyslainlatsa
Motivator
0 Karma

cfoleydivert
Explorer

I downvoted this post because agree with other down-voters. just want to know what this limit is set to, for my splunk cloud light instance.

0 Karma

prajaktk
New Member

I downvoted this post because wrong answer, question was about splunkcloud and not splunk enterprise

0 Karma

LWilliamson1
Explorer

I was more looking for what kind of hardware Splunk provides with their Cloud offering specifically. I understand concurrent search requirements, just not how many they make available to your instance with their Cloud platform.

0 Karma
Get Updates on the Splunk Community!

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Splunk Education Goes to Washington | Splunk GovSummit 2024

If you’re in the Washington, D.C. area, this is your opportunity to take your career and Splunk skills to the ...