After we upgraded from 8.0.7 to 8.2.3, we are having lots of problems with search performance. We noticed that the analytics workspace changed a great deal and we wonder if that could be causing the performance issue.
Now we have lots of searches queued - that didn't happen before. Also sometimes the maximum number of historical searches is exceeded and we end up having to restart Splunk. After the restart, our system runs okay for a while.
Any help will be appreciated.
I am told this problem is reflected in SPL-216787. We have been advised to upgrade to 8.2.4 and change the parameter job_default_auto_cancel to 62. I will update this question later to say if our problem has been solved.