Splunk® App for PCI Compliance

Installation and Configuration Manual

Acrobat logo Download manual as PDF

This documentation does not apply to the most recent version of PCI. Click here for the latest version.
Acrobat logo Download topic as PDF

Troubleshoot your deployment

This section provides tips for troubleshooting possible issues with your Splunk App for PCI Compliance deployment.

Other required apps

Splunk Enterprise implements some of its functionality through separate apps. Do not disable any of these apps:

  • learned
  • search
  • launcher
  • user-prefs

General performance

When adding indexes to the default search indexes do not include any summary indexes, as this can cause a search and summary index loop. See the PCI Compliance Manual FAQ in the PCI Compliance User Manual for details.

Where appropriate, you can improve performance of the Splunk App for PCI Compliance and reduce hardware requirements by limiting the indexes used by the app.

If the Splunk App for PCI Compliance is limited to a subset of indexes, all of the indexes it searches require admin access, as described in "Set up multiple indexes" in Managing Indexers and Clusters of Indexers.

Note: By default the search head will search over the "main" index.

Measuring system performance

You can use IOZone to measure system performance (it runs on Windows). IOzone will output the data in IOPS if the "-O" argument is specified.

Below is an example of IOzone invocation to store results in an Excel spreadsheet with IOPS:

iozone -s 4g -r 2k -r 4k -r 8k -r 16k -r 32k -O -b results.xls

Performance on UNIX systems

The search head that is hosting the Splunk App for PCI Compliance should be configured for high performance. UNIX systems should check the ulimit setting in particular, as this can artificially limit the operating system's capacity.

Other performance impacts include the Linux swappiness setting. Consult with your UNIX systems administrator for high performance build recommendations.

Other troubleshooting tips

  • Make sure you have the minimum (correct) version of Splunk Enterprise installed. See "Install Prerequisites" in this manual for more information.
  • Make sure you disable other apps on the search head you are using for the Splunk App for PCI Compliance. If you are using the Cisco apps (Cisco WSA, ESA, Firewalls, and so on), make sure to disable the saved searches. See the FAQ in this manual about Cisco add-ons for details.
Last modified on 26 October, 2015
Upgrade Splunk App for PCI Compliance

This documentation applies to the following versions of Splunk® App for PCI Compliance: 2.1.1

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters