Splunk Search

What are some of the recommended steps for general daily optimization/maintenance on splunk?

quahfamili
Path Finder

Hi all,

I had been using splunk for a period of time. However, I notice that the performance started to degrade as more indexes are added.

Do anyone have any recommended script or steps that i can do daily to improved performance.

I had search through this forum, there are many recommendation but mostly are specific to an issue. I am asking for some sort of general maintenance for splunk.

Thanks in advance.

0 Karma
1 Solution

renjith_nair
Legend

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...