Splunk® Enterprise

Workload Management

Acrobat logo Download manual as PDF

Splunk Enterprise version 8.0 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Monitor workload management using the monitoring console

The monitoring console provides a set of workload management dashboards that give you insight into various aspects of your workload management deployment. You can use these dashboards to view configuration information, track CPU and memory resource usage, and monitor activity details for both single instance and distributed deployments.

To view workload management dashboards:

  1. In Splunk Web, click Settings > Monitoring Console.
  2. Click Resource Usage > Workload Management.
  3. Select from the following dashboard pages:
    • Workload Management Overview
    • Workload Management Activity: Instance/Deployment
    • Workload Management Monitoring: Distributed

Workload Management Overview

The Workload Management Overview dashboard displays high-level information about your workload management deployment, including information about your underlying Linux system.

The Workload Management Status panel shows whether workload management is supported and enabled on your individual Linux instances. It also displays error messages that you can use to troubleshoot issues with your system configuration.

The Workload Pool Configuration panel lists all existing workload pools and specifies which pools are currently designated as the default search pool and default ingest pool.

The Deployment-Wide CPU Usage by Workload Pool and Deployment-Wide Physical Memory Usage by Workload Pool panels show CPU and Memory resource consumption respectively over time on a per pool basis. You can use these panels to monitor the total amount of resources that search processes are consuming within individual workload pools.

Monitoring workload pool resource consumption can help you provision resources efficiently and help you avoid assigning too many searches to a pool, which can degrade search performance.

Memory usage is an estimate only, based on simple addition of the amount of memory used by each process in a pool. Memory shared between processes can be counted repeatedly, which can produce an overestimate of memory usage in a workload pool.

Workload Management Activity: Instance/Deployment

The Workload Management Activity: Instance and Workload Management Activity: Deployment dashboards let you monitor CPU and Memory usage of individual workload pools on a per instance basis and across a distributed deployment, respectively.

The Workload Management Pool Limits panel shows the Memory Limit setting for each workload pool, as well as the average amount of Memory and CPU resources used by each workload pool. You can use this panel to monitor memory consumption within individual pools and make sure that memory usage stays within the existing memory limit.

The Memory Usage and CPU Usage panels let you monitor Memory and CPU usage by searches and Splunk core processes within individual workload pools over a specified time range. You can use these panels to monitor resource usage within search pools by a variety of parameters, including app, role, search type, and search mode. You can also monitor resource usage within the default ingest pool by process type and individual processes.

Median Memory usage.png

Workload Management Monitoring: Distributed

The Workload Management Monitoring: Distributed dashboard lets you monitor stats on triggered workload rule actions, including abort, move, and alert. You can use this dashboard to monitor the frequency with which searches are triggering workload rule actions and identify searches that might require additional optimization.

The dashboard provides a set of overview panels that show the number of searches aborted, the number of searches moved to alternate pools, and the number of searches triggering an alert over the last hour.

The Number of searches per action triggered panel shows the total number of searches that have triggered each type of action and the corresponding workload rule.

The Number of searches per action per action triggered over time shows the number of searches that have triggered an action over time and the corresponding workload rule.

The Overview of scheduled searches triggering rules panel lists each search that has triggered a workload rule action and the number of times the search has triggered the action.

WLM monitoring.png

For more information on workload rules, see Create workload rules.

Last modified on 14 October, 2020
Workload management examples
Monitor workload management using the splunkd health report

This documentation applies to the following versions of Splunk® Enterprise: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters