Monitoring Splunk

poor performance for metrics index

giotto69
Observer

Hi everybody

we are seeing bad performances in metrics indexes searches, in particular when a "group by" clause is used on dimensions with many values

Of course performance decrease as time interval being searched increases

We set up the metric rollup mechanism to aggregate raw values into 1 hour, with the idea of having better performance. Hard to believe: search performance is worse on the aggregated index than on the original one.

it seems that the insights of how metrics indexes are built heavily impact our searches.

Does anyone have any idea, or specific info on metric indexes beyond what's written in documentation?

thanks

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...

What's New in Splunk Cloud Platform 9.0.2208?!

Howdy!  We are happy to share the newest updates in Splunk Cloud Platform 9.0.2208! Analysts can benefit ...

Admin Console: A Single, Unified Interface for All Your Cloud Admin Needs

WATCH NOWJoin us to learn how the admin console can save you time and give you more control over the Splunk® ...