Splunk Search

reuse real time searches

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a situation where there are around 10 users that need to use for their job two o three dashboards containing each one 8-12 panels with real time searches.

This is a problem because I have not many logs (around 15-20 GBs/day) but I need very many resources to answer to the request (three indexers with 12 CPS each one aren't sufficiet to answer to the requests).

Is it possible, having realtime searches, to run them once and every user use results?

Bye.
Giuseppe

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Do you really need real-time searches? If only people will be reacting to the search results then real-time is probably not a necessary waste of resources. Consider switching them to scheduled searches running every minute or two. Then each dashboard can reuse the results of the scheduled searches.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Finally customer accepted to schedule searches instead use Real Time Searches!
Thank you.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...