Good Assets and Identities make for big bundles

Having great and informative data will make for some hefty lookups. I’ve heard from a few customers that run into this rather than plan for it so let us talk about the levers we need to pull.

  • Don’t wait around upgrade to Splunk Enterprise 6.5.2+ Now is the time
  • Don’t wait any longer upgrade to Splunk Enterprise Security 4.5.1 the dev team invested in improvements to assets and identities lookups that also improve by decreasing the size of the merged lookups.
  • Update server.conf on the indexers and search head cluster peers.

[httpServer]

max_content_length = 1610612736 # 1.5 GB

  • Update distsearch.conf to better replication on the SH/SHC
[replicationSettings]
# 1.5 GB with encoding room this will increase the memory utilization while decreasing CPU utilization
maxMemoryBundleSize = 1700 
#1.5 GB to match server.conf on the other side
maxBundleSize = 1536