Reporting

Is it known that disabled saved searches cause poor performance?

bsizemore
Path Finder

Hello, one of our engineers through trial and error discovered something that has been hobbling our Splunkfrastructure for months. We had 300 saved searches on one of our servers, 150 of which were disabled. He deleted all 150 disabled saved searches, and now our platform’s performance is orders of magnitude greater. Is this well known?

Tags (2)
1 Solution

bsizemore
Path Finder

Well, this was our experience.

View solution in original post

0 Karma

bsizemore
Path Finder

Well, this was our experience.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

No skipped searches that I know of, rather sluggish UX... I'll check that nonetheless.

bsizemore
Path Finder

If you have piles of disabled saved searches, and you have numerous skipped searches, as we had, maybe you can try it an let us know how that works out. We are on 6.0.3.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Ah... I wasn't thinking of a solution, just wondering if I should try this on some SHP environment that has become a bit sluggish lately 🙂

bsizemore
Path Finder

The host in question is an isolated job server. We do use pooling of search heads, which this host is not a member of.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Are you using Search Head Pooling?

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...