Splunk Search

Why is the memory usage high on the indexer when running a simple stats count search?

marcusnilssonmr
Path Finder

The search index=main | stats count is taking a lot of memory on the indexer when there are lots of events. Isn't the indexer doing an incremental reduce to produce the count? Why would it need a lot of memory?

yannK
Splunk Employee
Splunk Employee

Compare the search mode.
For a basic search like this one, make sure that you are running the search in "fast mode" not in "verbose or smart mode",
It may do a different if you have many automatic fields extractions / lookups.
What is the nature of your data, are they key/values, or do they require complex regexes to parse at search time ?

About the memory map reduce, this would be more relevant if you have several indexers.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...