Splunk Search

How to find thrput of data being searched in Splunk?

nravichandran
Communicator

We are planning to for a F5 load-balancer to be placed in front of the search heads. For sizing, how can I find out the following:
1. Current throughput for searches
2. Max thrput
3. Number of user sessions

The management console (which aggregates data from the whole distributed environment) shows data for the indexers, index, sourcetypes but no the user activity. Is there any query to find out the above?

Thank you in advance.

Tags (3)
0 Karma

nickhills
Ultra Champion

You could install the stream forwarder on your searchheads and profile your current usage over a few days.

If my comment helps, please give it a thumbs up!
0 Karma

nravichandran
Communicator

Since it is production it cannot be done.

0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...