Splunk Search

reuse real time searches

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a situation where there are around 10 users that need to use for their job two o three dashboards containing each one 8-12 panels with real time searches.

This is a problem because I have not many logs (around 15-20 GBs/day) but I need very many resources to answer to the request (three indexers with 12 CPS each one aren't sufficiet to answer to the requests).

Is it possible, having realtime searches, to run them once and every user use results?

Bye.
Giuseppe

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Finally customer accepted to schedule searches instead use Real Time Searches!
Thank you.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...