...ouse systems. I know that Splunk not a RDB and that this is an OS configuration, but would performance be increased by decreasing or increase the Disk Block Size? By default I believe NTFS and ext2/3 a...
Hello!
I have a small distributed deployment consisting of 2 search heads (16 cores each) and 2 indexers (24 cores each). There are about 900 saved searches to govern critical alerting with the a...
...andling large numbers of assets and/or identities. I increased the maximum bundle size to 4GB, but still had to distribute the entire huge bundle every time an identity changed. Is there an o...
...ay to increase the size of the max_size_kb value? I can't find any setting within limits.conf or any other files which will affect this. There must be a way to improve the performance when there are l...
...opies would be necessary?
I'm hoping to be able to use an all-in-one Splunk instance (so no indexer clustering) but I have no means to realistically test the search performance/experience with 20-4...
...uch as Forefront security logs
Scripted inputs:
• Performance monitoring data on all Mailbox Store servers
• Senderbase/reputation data. (This feature needs internet access to function, as i...
We're considering moving our Splunk environment from AIX to a Linux x86 box for performance reasons. My particular department uses a tiny 500 MB license (carved out of a larger license).
We do n...
I have a large index cluster with bare metal machines that have different hardware configurations. The number of SDD's, their size, andperformance specs differ across the indexers. So what is t...
Hello Splunkers!!
As per the below mentioned code, I want to change the font size of the text which is created through eval ( | eval text= "The performance is determined by the number of c...