Monitoring Splunk

poor performance for metrics index


Hi everybody

we are seeing bad performances in metrics indexes searches, in particular when a "group by" clause is used on dimensions with many values

Of course performance decrease as time interval being searched increases

We set up the metric rollup mechanism to aggregate raw values into 1 hour, with the idea of having better performance. Hard to believe: search performance is worse on the aggregated index than on the original one.

it seems that the insights of how metrics indexes are built heavily impact our searches.

Does anyone have any idea, or specific info on metric indexes beyond what's written in documentation?



Labels (1)
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!