Splunk Search

Load of index Data statistics on starting page?

tweaktubbie
Communicator

Just wondering when looking into performance improvements... After logging in to Splunk (...app/launcher/home), you see on the right some fancy statistics that are interesting for the first times, but after that makes one wonder... Like:

Events Indexed: 7,725,934,214
Earliest Event: 6 years ago
Latest Event: Now

It keeps on updating the numbers for quite some time, giving the impression doing some background query.
Not relevant for all users. So: anyone any knowledge of the load this causes as every user gets this?

Can this be disabled for all users and how?

Tags (3)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The load generated by this is very low - it's not actually looking at those seven billion events but only at counters / meta-data.

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

Observability Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestSplunk APM's New Tag Filter ExperienceSplunk APM has updated ...

Security Newsletter Updates | March 2023

 March 2023 | Check out the latest and greatestUnify Your Security Operations with Splunk Mission Control The ...