Reducing search load
Significant reductions in search load and better resource allocation lead to a highly efficient and cost-effective Splunk environment. There are many strategies you can apply to optimize search load and maximize SVC/vCPU utilization. These include refining search queries and dashboard panels, leveraging summary indexing to pre-aggregate data, implementing search-time filters, and using data model accelerations (DMA). You can also control time ranges, more effectively manage indexes, limit concurrent searches, and employ search head clustering. Lastly, you should regularly monitor of resource usage and keep your Splunk deployment up-to-date. The strategies provided in this pathway will help you accomplish all these varied goals. You can work through them sequentially or in any order that suits your current level of progress in reducing search load.
This article is part of the Reduce Costs Outcome. For additional pathways to help you succeed with this outcome, click here to see the Reduce Costs overview.