Splunk Search

Ldapsearch query speed difference

omershira
Explorer

Greetings,

We have a Splunk Environment with 3 Search Head in the SHC.

We try to perform an ldapsearch command using the SA-LDAPsearch 3.0.2 add-on.

The search takes a devastating 18-19 seconds to load on the first and third Search Heads but on the second one it takes 3-4 seconds.

We inspected the job and saw that according to the search.log the second SH indeed takes milliseconds between each action meanwhile the other two take 2-3 seconds between each internal step.

We tried to speed up the ldapsearch with the "attrs" and "basedn" settings but even though it helped a little bit, 19 seconds is still too much time...

The three search heads have identical resources and settings.

What can be the cause of this major difference and what can I do to speed-up the ldapsearch or in what way can I debug it better?

 

Thanks,

OmerShira

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Exciting News: The AppDynamics Community Joins Splunk!

Hello Splunkers,   I’d like to introduce myself—I’m Ryan, the former AppDynamics Community Manager, and I’m ...

The All New Performance Insights for Splunk

Splunk gives you amazing tools to analyze system data and make business-critical decisions, react to issues, ...

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...