Monitoring Splunk

Benchmarking search: indexer vs search head.

Michael_Wilde
Splunk Employee
Splunk Employee

I've just setup a search head that will search across 2 load balanced indexers.  I'd like to compare the execution time of equivalent searches

 

1) when run on the new search head

2) when run our "old way" on the indexers themselves.

  Is there something I could use that tells me how long the search takes to execute?  Something maybe like the Splunk equivalent of the "time" command on Unix/Linux?

gkanapathy
Splunk Employee
Splunk Employee

You can use the "inspect search" dialog which is available from the flashtimeline view "Actions" menu. If you pull the search results from the "jobs" page, it should pop into the flashtimeline view (usually) and you should be able to get to the menu item from there.

You can of course also use the unix time command with CLI searches.

Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...