Deployment Architecture

mulitple searchable copies in splunk...

a212830
Champion

Hi,

Does having multiple searchable copies of your index make splunk searches go faster? I've heard different responses on this question.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Short answer: It depends, but usually not.

Long answer: In a regular old cluster there's one primary copy of each bucket that's queried by searchheads. Other searchable copies may exist, but they're not used. Using them wouldn't speed up most searches either, because the other search peers are busy serving up data from other buckets they may be primary for.
However, in a multi-site cluster search affinity lets search heads use a searchable copy in their own site, indeed speeding up searches. That's not achieved by querying one bucket in multiple search peers though, but rather by choosing one copy from a nearby search peer instead of a distant - and therefore slower - one.

gkanapathy
Splunk Employee
Splunk Employee

Just to be clear, it never makes a single search run faster. But as martin_mueller says, it can increase capacity if you have a multi-site cluster, so the total amount of searching can go faster. It is possible that future optimizations and improvements to Splunk will allow increased capacity even without multi-site clustering, but that is not the case in the current (6.1) version.

0 Karma

a212830
Champion

Thanks. Interesting - definitely NOT what I'm being told by Splunk SE's...

0 Karma

yannK
Splunk Employee
Splunk Employee

I confirm, for now on splunk 6.0 and 6.1 even if you have multiple searchable bucket copies only one will be searched.
The reason for having search-factor>1 is to have the some buckets copies immediately ready when an indexer is lost. And not have to wait for the preparation to make one of the copies a searchable copy.

Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...