Splunk Search

What are some of the recommended steps for general daily optimization/maintenance on splunk?

quahfamili
Path Finder

Hi all,

I had been using splunk for a period of time. However, I notice that the performance started to degrade as more indexes are added.

Do anyone have any recommended script or steps that i can do daily to improved performance.

I had search through this forum, there are many recommendation but mostly are specific to an issue. I am asking for some sort of general maintenance for splunk.

Thanks in advance.

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

Happy Splunking!

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

Happy Splunking!
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...