Deployment Architecture

Where do I configure parallelization settings in an indexer clustering environment?

ontkanin
Path Finder

Hi there,

I am trying to configure my Splunk environment (1xSH, 2xIndexers (cluster), 1xClusterMaster) to use parallelization, as described in Parallelization settings.

While I understand that parallelIngestionPipelines should be configured on indexers, I am kind of not very sure where the batch_search_max_pipeline settings should be configured.

  • on Indexers?
  • on Search Head?
  • on Indexers and Search Head?

The documentation is not very clear on that, or I'm not getting it.

Thank you

0 Karma
1 Solution

sk314
Builder

From the docs at http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/Configurebatchmodesearch#Configure_batch...

You can enable and configure batch mode search parallelization with an additional set of limits.conf parameters. This is an indexer-side setting. It needs to be configured on all of your indexers, not your search head(s).

View solution in original post

sk314
Builder

From the docs at http://docs.splunk.com/Documentation/Splunk/6.4.0/Knowledge/Configurebatchmodesearch#Configure_batch...

You can enable and configure batch mode search parallelization with an additional set of limits.conf parameters. This is an indexer-side setting. It needs to be configured on all of your indexers, not your search head(s).

ontkanin
Path Finder

Thanks a lot sk314. I must have been blind for not seeing that sentence. I really appreciate your help.

0 Karma

sk314
Builder

You are welcome. To be fair, It's a couple of links down the chain...

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...