nerdexam
Splunk

SPLK-3003 · Question #48

A customer has a multisite cluster (two sites, each site in its own data center) and users experiencing a slow response when searches are run on search heads located in either site. The Search Job…

The correct answer is A. Configure site_search_factor to ensure a searchable copy exists in the local site for each search. https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Sitesearchfactor

Search Performance and Optimization

Question

A customer has a multisite cluster (two sites, each site in its own data center) and users experiencing a slow response when searches are run on search heads located in either site. The Search Job Inspector shows the delay is being caused by search heads on either site waiting for results to be returned by indexers on the opposing site. The network team has confirmed that there is limited bandwidth available between the two data centers, which are in different geographic locations. Which of the following would be the least expensive and easiest way to improve search performance?

Options

  • AConfigure site_search_factor to ensure a searchable copy exists in the local site for each search
  • BMove all indexers and search heads in one of the data centers into the same site.
  • CInstall a network pipe with more bandwidth between the two data centers.
  • DSet the site setting on each indexer in the server.conf clustering stanza to be the same for all

How the community answered

(27 responses)
  • A
    56% (15)
  • B
    7% (2)
  • C
    11% (3)
  • D
    26% (7)

Explanation

https://docs.splunk.com/Documentation/Splunk/9.0.1/Indexer/Sitesearchfactor

Topics

#multisite cluster#site_search_factor#search performance#bandwidth optimization

Community Discussion

No community discussion yet for this question.

Full SPLK-3003 Practice