Monitoring Splunk

Deployment Monitor Scalability

jonathanmorcom
Explorer

I've just done a complete re-install of this app on a new server. Only other app running on the new server is Deployment Server.

I've dropped the summary index retention to 1 month.

It still is almost un-usable... Incredibly slow load times etc. We are quite a big site, with a large amount of data so it could be related to the scale of the data it has to process from the indexers perhaps. Though it did seem to work quite a bit better on version 4.

Has anyone else had issues?

1 Solution

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

View solution in original post

mkinsley_splunk
Splunk Employee
Splunk Employee

Try taking a look at your Search Jobs for Deployment Monitor. If you click on Jobs in the upper right menu, and then select App:Deployment Monitor, Owner: All, you will be able to inspect the App Search jobs. Click on inspect and that will bring up a window detailing the performance of a given search job.

In particular, note where the majority of time is spent for the job, and also note the ammount of time spent in command.search.rawdata vs command.search.summary. If you see that most of the time is spent in searching rawdata, that would be an indicator that Report Acceleration Summaries are not being used.

jonathanmorcom
Explorer

I might give this a shot next week. For now have the old version happily chugging along. Thanks for the advice!

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...