Splunk Search

realtime search scaling

splunkbacon
Explorer

I have read about some limits you can come across when doing realtime searches. When trying to scale this out should you be editing these configuration files and increasing resources on the searchhead or the indexers? It seems like the indexers are doing all of the real searching. What exactly does the searchhead actually do in terms of the under the hood technical part of a search? Does it exist only to host the web gui and distribute searches to indexers?

Tags (1)
0 Karma

MuS
Legend

Hi splunkbacon,

Have a read here https://conf.splunk.com/files/2016/slides/it-seemed-like-a-good-idea-at-the-time-architectural-anti-... with special focus on slide 12 😉
But yes, the indexers are the real bottleneck because each real time search takes up one CPU.

To prevent current and future headaches, you should forget about real time searches completely and run your alerts over short time ranges on short intervals.

Hope that helps ...

cheers, MuS

splunkbacon
Explorer

I'm not sure I understand after reading that what I was getting at.

There are some limits with searching in regards to how many cores you have, and how many searches per core etc that determine how many realtime searches you can have going on. I'm not sure if these limits apply to only the searchhead or the indexer or if you should be updating them on both. Are the indexers the real bottleneck for realtime searches? I run into a lot of issues with realtime searches not firing with no indication as to why even though the search returns results when looking at a timespan.

0 Karma

HiroshiSatoh
Champion

If you read this part of the manual you will know what you are doing.

https://docs.splunk.com/Documentation/Splunk/7.2.5/Search/Writebettersearches
->Command types and parallel processing

For example, sorting by a large amount of data consumes more resources on the search head.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...