Splunk Search

How to find thrput of data being searched in Splunk?

nravichandran
Communicator

We are planning to for a F5 load-balancer to be placed in front of the search heads. For sizing, how can I find out the following:
1. Current throughput for searches
2. Max thrput
3. Number of user sessions

The management console (which aggregates data from the whole distributed environment) shows data for the indexers, index, sourcetypes but no the user activity. Is there any query to find out the above?

Thank you in advance.

Tags (3)
0 Karma

nickhills
Ultra Champion

You could install the stream forwarder on your searchheads and profile your current usage over a few days.

If my comment helps, please give it a thumbs up!
0 Karma

nravichandran
Communicator

Since it is production it cannot be done.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...