Splunk Search

reuse real time searches

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a situation where there are around 10 users that need to use for their job two o three dashboards containing each one 8-12 panels with real time searches.

This is a problem because I have not many logs (around 15-20 GBs/day) but I need very many resources to answer to the request (three indexers with 12 CPS each one aren't sufficiet to answer to the requests).

Is it possible, having realtime searches, to run them once and every user use results?

Bye.
Giuseppe

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Finally customer accepted to schedule searches instead use Real Time Searches!
Thank you.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...