Splunk Search

Is search performance affected by number of warm buckets?

DDerck
New Member

I would like to know if search performance could be increased by moving buckets from warm to cold?
My main index contains approx 4,500,000,000 events, with the oldest from Nov 2013 and is composed of around 235 buckets.

Will I gain anything if I move buckets to cold state?

0 Karma

Yasaswy
Contributor

Hi, This will depend on kind of searches that will run:

If most of your searches access only few weeks or few months of data, then moving "older" data/buckets to cold will result in search performance improvement as there is now less data to search through. If the searches use /need to access all the historical data, then moving data to cold will negatively impact your searches... as the searches will now have to fetch data from cold buckets.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...