Splunk Search

What are some of the recommended steps for general daily optimization/maintenance on splunk?

quahfamili
Path Finder

Hi all,

I had been using splunk for a period of time. However, I notice that the performance started to degrade as more indexes are added.

Do anyone have any recommended script or steps that i can do daily to improved performance.

I had search through this forum, there are many recommendation but mostly are specific to an issue. I am asking for some sort of general maintenance for splunk.

Thanks in advance.

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

Happy Splunking!

View solution in original post

renjith_nair
SplunkTrust
SplunkTrust

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

Happy Splunking!
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...