Splunk Search

What are some of the recommended steps for general daily optimization/maintenance on splunk?

quahfamili
Path Finder

Hi all,

I had been using splunk for a period of time. However, I notice that the performance started to degrade as more indexes are added.

Do anyone have any recommended script or steps that i can do daily to improved performance.

I had search through this forum, there are many recommendation but mostly are specific to an issue. I am asking for some sort of general maintenance for splunk.

Thanks in advance.

0 Karma
1 Solution

renjith_nair
Legend

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

---
What goes around comes around. If it helps, hit it with Karma 🙂

View solution in original post

renjith_nair
Legend

Hi @quahfamili ,
You might not find a single click solution to optimize the entire infrastructure because the performance issues might be of different reasons. If the increase in indexes is the main reason of performance degradation, you should re-look at the resource capacity. In a more general way,

Once you could identify the area of improvement and if it's recurring, you could automate

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...