Last time I used it was almost a decade ago and it was rubbish, queries took 10-40 minutes to complete.
Last time I used it was almost a decade ago and it was rubbish, queries took 10-40 minutes to complete.
Your queries or infrastructure were not optimized. It’s very fast when optimized.
It was Splunk managed and configured, so I would have thought it optimized, but I guess they made more money from it not being optimized.
If I remember right then we were throwing about 200+ GB at it a day.
But you have to learn to use it, if you don't give it an index and a sourcetype that will slow it down, and like ES leading wildcards slow things down. The fastest searches are simple terms like a word or an IP.
From the general responses it sounds like we got unlucky with a dud implementation.
It never got the love it deserved and I could absolutely believe that its Splunk cluster suffered as a result. RIP
We were only sending a small subset of our logs to it so about 200+ GB a day. Our Linux box with spinning disks could grep the full set of logs much faster than querying Splunk, so I don't think anyone really used it.
I work as a Splunk integrator and here's what I often see:
1. Customer installs Splunk with a qualified Splunk or third-party architect team. The deployment works well.
2. Customer adds infrastructure to the deployment. Splunk slows down. License costs go up.
3. Customer chooses between outside help or DIY. DIY rarely works.
4. Customer now needs outside help. Now Splunk is very slow and expensive, and now it will cost a lot to tune it.
Splunk, the company, is in a tough spot for several reasons: rotating c-level cast, unpopular changes to license model, bad acquisitions. The product is still best in class but tough to keep optimized.
A firm with a competent IT team is unable to get splunk to work and only "outside help" can make the product work?
Given splunks license costs are tied to data ingested, how do you integrate new infrastructure to the deployment and not have license costs go up?
Way to sell us on Splunk?
We finally got rid of it a few years later, but for the entire time we had it, it was a constant "round hole square peg" problems. Each time the consultants assured us Splunk could do what we needed, each time it could not.
Just that it looks like most people here had a good experience and we had a bad one for some reason.
The guy we had help us tune our clusters after I rebuilt them all was also very good. Fortunately I'd done most everything by the books and we overkilled the nodes with hardware (we had some older hypervisor nodes lying around I stole for Splunk).