Skip to main content
Solved

LHE search considerations: focus on ingest volume, not search

  • July 23, 2026
  • 2 replies
  • 0 views

This message originated from Cribl Community Slack.
Click here to view the original link.

Should any consideration be given to how often a LHE will be searched when choosing a size? Where does search run? The leader? Instances that are spun up on demand?

Best answer by Roman Trusov

No, only the ingest volume -- unless you have a truly incredible volume of searches, LHE that can ingest everything you give to it should be able to search everything without an issue. LHE is what doing the heavy lifting there, leader is doing some work, but mostly dispatching the jobs

2 replies

  • New Participant
  • Answer
  • July 23, 2026
No, only the ingest volume -- unless you have a truly incredible volume of searches, LHE that can ingest everything you give to it should be able to search everything without an issue. LHE is what doing the heavy lifting there, leader is doing some work, but mostly dispatching the jobs

I'll add some nuance to the answer from @user. Primaty compute for LHE searches runs on the LHE, so the larger it is, the more spare compute you have for Search performance, for a given Ingest load. Running searches will share any unused capacity on the Engine, so if you've got a larger Engine, you've got more spare capacity for Search. While this is not normally a factor in day-to-day searching, for high-CPU-demand searching (complex KQL, large volume searches, multiple simultaneous scheduled searches, dashboards with many panels, etc), that extra compute capacity on the LHE is definitely a plus, especially when you hit the Large and above sizes.