Reporting

What's the average throughput that Splunk can handle to create an up to date real-time report with a maximum delay of 15 seconds??

manuelparedes
New Member

I'm new at Splunk and I'm trying to develop a real-time reporting tool that keeps track of around 50k records per second, but I've noticed that Splunk has some difficulty to make reports in real-time with this amount of records. Does anyone know the average throughput that Splunk can handle to make a good and up to date real-time report with a maximum delay of 15 seconds

0 Karma

Richfez
SplunkTrust
SplunkTrust

There are a lot of variables here that I don't think can be properly answered without testing on your own system, but maybe this will help.

I had a slow, old server that could real-time syslog messages from our firewall at perhaps 5000 per second with just a couple of seconds of lag. Most of that lag was NOT Splunk's fault, though, it was traced one day to the ASA not prioritizing syslog stuff well enough so wouldn't get them to Splunk in a timely manner. Splunk itself had nearly zero lag and what was there seemed to just be lag on the browser/client rendering side.

I don't know the typical amount of lag in reading files, so there's another place for things to go slightly slow - how are the 50k records per second getting into Splunk? Is it coming in via syslog and the syslog application is buffering?

Also, the SIZE of the records needs to be taken into consideration, too.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...