Splunk® Enterprise

Workload Management

Acrobat logo Download manual as PDF


Splunk Enterprise version 7.3 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk® Enterprise. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

About workload management

Workload management is a policy-based system resource manager that lets you allocate compute and memory resources to search, indexing, and other processes in Splunk Enterprise.

With large numbers of searches running concurrently across your deployment, inefficient allocation of system resources can impact search execution, and cause latency, skipped searches, and other performance issues. In some cases, high-priority searches might not have adequate system resources, while trivial searches are allocated too much.

Workload management addresses these issues and helps you optimize resource usage by letting you control the amount of system resources allocated to searches and other processes in Splunk Enterprise.

Workload management lets you:

  • Reserve system resources for search, indexing, and other splunkd processes.
  • Prioritize critical search workloads.
  • Prevent over-usage of system resources.
  • Avoid data-ingestion latency due to heavy search load.
  • Allocate resources by categories based on process type.
  • Create rules to control access to resources based on app, role, index, and user.
  • Assign accelerated reports and data models to workload pools.

To learn more about workload management, see How workload management works.

For Linux configuration prerequisites, see Set up Linux for workload management.

For workload management configuration instructions, see Configure workload management.

To learn how to allocate resources to searches, see Assign searches to workload pools.

Last modified on 19 July, 2019
  NEXT
How workload management works

This documentation applies to the following versions of Splunk® Enterprise: 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters