Splunk Search

Recommended maximum concurrent searches?

ankithreddy777
Contributor

whats the recommended maximum concurrent searches overall can be performed if we have 40 indexers in a cluster. There are 10 search heads.

0 Karma

DavidHourani
Super Champion

did you get an answer to your question ?

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

The answer to that significantly depends on your average search execution time (which depends on search complexity and event distribution) and the number of cores you have in both, search heads and indexers.

In other words, we can't really answer this question without knowing these things.

ankithreddy777
Contributor

May I get an rough estimation.
Average search time 30 secs with simple searches for statistics.
number of cpus=24 on search heads and indexers
indexers =40 in a cluster
search heads = 10

What can be the rough estimate of Max concurrent searches can be performed indexers using SH.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Your search head tier has the capacity to produce 300 concurrent searches (with default settings, i.e. #of cores+6).
If those are 24 physical cores with hyperthreading enabled, make that 540 concurrent searches (48+6*10).
So that's your maximum theoretical concurrent search load the search tier can produce.

Whether your indexers can handle that depends on how quickly each indexer can complete its part of each search. A lot will depend on your search type, time frames, disk I/O speed, event distribution, etc.
Any rough estimate would largely be a best guess and of limited use.

30 seconds for a "simple search for statistics" seems a lot, btw.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...