Knowledge Management

10 billion indexed events

garyramah
New Member

Anyone out there have 10 Billion indexed events?
I do and I think it's slowing down my Splunk.

Tags (2)
0 Karma

gekoner
Communicator

I'll concur with piebob and erga00. I also have over 10B events indexed without issue.
If you have a single server on older hardware with default network setting, you might be seeing issues during large searches.
Things that will be helpful in understanding why you might be seeing slowness;

number of Splunk servers:
If more than 1 server, what roles do they operate:
server OS:
server hardware (memory, CPU, NIC (speed and #)):
splunk version:
splunk LFCs or UFCs reporting to indexers:
index=* host=* earliest=-7d | table host | dedup host

number of searches run (Expensive searches):
Search > Search Activity > Search details

0 Karma

erga00
Path Finder

Agree with piebob, you'll need to provide more details if you want any meaningful replies.

To answer your original query, we're up to 52 billion events without any trouble.

piebob
Splunk Employee
Splunk Employee

can you please provide more details? what exactly is happening? what are you trying to learn here?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...