Splunk?

Has anyone ever tried out Splunk on their Linode?

I just got my first Linode up and running on Monday and have transferred several small web sites over to it. I was wanting to test out some reporting packages so that I could easily keep an eye on which sites are consuming the most resources. Splunk is pretty snazzy, but running on my test server, it's consuming lots of resources. Granted, there are 5 years of logs as opposed to a few days, but I'm still wondering if it may be a CPU, memory, or IO burden over time.

If anyone has tried, are there any tuning tips they may recommend to make it Linode-friendlier?

If not, I may test the waters a little bit with it and see what the reaction is.

1 Reply

Here's a video tip that might help a bit: http://www.splunk.com/article/2183

There are several ways to tune indexing performance with Splunk. By default it will index on any fields it identifies in the access_combined source types. (I assume this is what you are indexing.)

You may want to run what we call summary indexes to generate web analytics reports. There is another video tip that discuss that subject: http://www.splunk.com/article/2514

BTW, you'll want to make sure you are running the latest build (3.2.4 as of this post). Because Linode is a VM solution you can expect disk access to be a bit slow, and in turn affect Splunk's indexing performance.

Reply

Please enter an answer
Tips:

You can mention users to notify them: @username

You can use Markdown to format your question. For more examples see the Markdown Cheatsheet.

> I’m a blockquote.

I’m a blockquote.

[I'm a link] (https://www.google.com)

I'm a link

**I am bold** I am bold

*I am italicized* I am italicized

Community Code of Conduct