Splunk Search

Searches & Reports

itsomana
Path Finder

I have configured a dashboard with 28 boxes which change from green to red depending on the parameters of the saved search. The dashboard is configured to refresh every three minutes.

The saved searches relating to the 28 boxes are configured with a time range of of -5m to now. Half a dozen of these are scheduled to run every five minutes. If an event occurs as outlined in the saved search Spunk will then email certain individuals.

I am trying to establish if there would be too much overhead on the splunk server by configuring the saved searches and reports this way?

Tags (2)
0 Karma

kdenton
Path Finder

That's a hard question to answer as it really depends on what other searches are taking taking up resources at the time.

Here is an article I used when I did something similar for a client.

http://www.splunk.com/wiki/Community:SplunkTuningFactors

I found to spread my data into separate indexes as well as use some summary indexing helped a lot to speed things up.

Bottom line, is you will need to try it and see how things go, but keep in mind that when those searches are running every 5 minutes this also takes resources.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...