Splunk Cloud Platform

Splunk Cloud Platform Admin Manual

Manually assign searches to workload pools

Using workload rules to assign searches to workload pools automatically is the recommended method for allocating resources. You can however also manually assign searches to workload pools.

This page shows you how to assign searches to workload pools manually. For detailed instructions on how to assign searches to workload pools automatically using workload rules, see Configure workload rules.

To assign searches to workload pools manually, you must have list_workload_pools and select_workload_pools capabilities.

Assign a scheduled search to a workload pool manually

You can assign a scheduled search to a workload pool using Splunk Web, as follows:

  1. Click Settings > Searches, Reports, and Alerts.
  2. Find the specific saved search, and click Edit > Advanced Edit.
  3. In the Workload Pool field, enter the name of the pool.
  4. Click Save.

Assign an ad hoc search to a workload pool manually

You can assign an ad hoc search to a workload pool using Splunk Web, as follows:

  1. In the Search bar, enter your ad hoc search string.
  2. Select a workload pool from the menu.
  3. Run the search.
    The ad hoc search job runs in the specified workload pool.
    The image shows the workload pool drop-down menu on the search bar. The menu lists the available pools to which you can assign an ad hoc search.
  4. Click Job > Inspect Job > Search job properties.
  5. Confirm that the ad hoc search ran in the specified pool. For example:
    The image shows a list of search job properties, including the name of the workload pool in which the ad hoc search job ran.

Assign accelerated reports to workload pools manually

You can assign any report that qualifies for acceleration to a workload pool manually.

Assigning an accelerated report to a workload pool with ample CPU and memory resources can help you minimize performance issues that can occur during report acceleration, which can be resource-intensive.

To assign an accelerated report to a workload pool using Splunk Web:

  1. Click Settings > Searches, Reports, and Alerts.
  2. Find the report you want to accelerate and click Edit > Edit Acceleration.
  3. Select the Accelerate Report checkbox.
  4. Select the Summary Range for the report acceleration.
  5. Select a workload pool from the menu.
  6. Click Save.

For more information on report acceleration, see Accelerate reports in the Splunk Enterprise Reporting Manual.

Assign accelerated data models to workload pools manually

You can assign an accelerated data model to a workload pool using Splunk Web, as follows:

  1. Click Settings > Data models.
  2. Find the data model you want to accelerate and click Edit > Edit Acceleration.
  3. Select the Accelerate checkbox.
  4. Select the Summary Range for the data model acceleration.
  5. Select a workload pool from the menu.
  6. Click Save.

For more information on accelerated data models, see Accelerate data models in the Splunk Enterprise Knowledge Manager Manual.

Last modified on 27 October, 2020
Configure admission rules to prefilter searches   Workload Management examples

This documentation applies to the following versions of Splunk Cloud Platform: 8.2.2112, 8.2.2201, 8.2.2202, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308, 9.1.2312, 9.2.2403, 9.2.2406 (latest FedRAMP release), 9.3.2408


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters