Splunk Search

Splunk cloud - AWS - COncurrent searches

dhivyam
New Member

say, I have a splunk cloud,, Splunk as a service running in AWS with a daily index volume of 10 GB data per day. what is the maximum number of concurrent searches allowed? if there is any performance in concurrent searching, how to scale up?

0 Karma

woodcock
Esteemed Legend

Search capability, including concurrency has nothing to do with indexed volume. It is mostly constrained by CPU cores on the search head, plus settings, intersecting with actual demand. Read more here:
https://www.rfaircloth.com/2017/12/12/tuning-splunk-when-max-concurrent-searches-are-reached/

0 Karma

dhivyam
New Member

Thanks much for you response.
I understood from the docs that concurrent searches are related to CPU cores but If it's a Splunk enterprise version we have control over infrastructure. when it's Splunk cloud where do not know about the CPU cores/infra, how many concurrent searches are allowed with better performance?

0 Karma

woodcock
Esteemed Legend

Math is not the right approach here. Instead monitor for logs that clearly indicate either queued or skipped searches. If you have these, you have some kind of concurrency problem.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...