Splunk Search

reuse real time searches

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a situation where there are around 10 users that need to use for their job two o three dashboards containing each one 8-12 panels with real time searches.

This is a problem because I have not many logs (around 15-20 GBs/day) but I need very many resources to answer to the request (three indexers with 12 CPS each one aren't sufficiet to answer to the requests).

Is it possible, having realtime searches, to run them once and every user use results?

Bye.
Giuseppe

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Finally customer accepted to schedule searches instead use Real Time Searches!
Thank you.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...