<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Instances Utilizing HIGH CPU Usage in VMware Environment in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568102#M10069</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Interesting solution. I believe it might be worth a try. If it does solve the problem I will let you know.&lt;/P&gt;&lt;P&gt;However, I do see one possible fallacy to your solution. I may run into a situation where I cut the CPU cores in half and the VM continues to maximize the resource available. Then I would have to increate it back to where it was originally.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2021 17:06:19 GMT</pubDate>
    <dc:creator>sokngoc</dc:creator>
    <dc:date>2021-09-22T17:06:19Z</dc:date>
    <item>
      <title>Splunk Instances Utilizing HIGH CPU Usage in VMware Environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/567917#M10048</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;Any help would be appreciated. We have 4 Splunk instances that work together in tandem.&lt;/P&gt;&lt;P&gt;All four servers are Virtual Machines running Red Hat Enterprise Linux 8 Splunk Enterprise 8.2.2. VCenter is 6.7 with 4 ESXI Host each running 6.7 as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Four Splunk VMs are running very high CPU capacity at all times:&lt;/P&gt;&lt;P&gt;45.8 GHz&lt;/P&gt;&lt;P&gt;83.44 GHz&lt;/P&gt;&lt;P&gt;45.6 GHz&lt;/P&gt;&lt;P&gt;83.82 GHz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is basically running our ESXi Hosts to full capacity. I logged onto each server and ran the top -i command and each server states very low CPU usage.&lt;/P&gt;&lt;P&gt;Does anyone have any recommendations? Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 22:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/567917#M10048</guid>
      <dc:creator>sokngoc</dc:creator>
      <dc:date>2021-09-21T22:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Instances Utilizing HIGH CPU Usage in VMware Environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/567930#M10052</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can you please describe your deployment? I.E What roles the servers are. how many indexers, are they clustered. Are you using ES/ISTI.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;theTech&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 01:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/567930#M10052</guid>
      <dc:creator>thetech</dc:creator>
      <dc:date>2021-09-22T01:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Instances Utilizing HIGH CPU Usage in VMware Environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568036#M10064</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;when you are running Splunk on VMWare VM's I have seen that in some cases, if you have reserve too much vCores + mem for individual VMs, this could be the end result. You should remember that when VMWare schedules those nodes it needs to clean memory (on EXSi) etc. before it start to run "new" vm. Especially if you have overbooked you ESXi nodes as it's usually recommended you have "shoot your foot" ;-( with splunk nodes.&lt;/P&gt;&lt;P&gt;You should try to decrease number of vCores and memory if possible and then check the situation. Usually &amp;nbsp;I try to us as less resources on VMs as possible and increase those when needed.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 13:19:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568036#M10064</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-22T13:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Instances Utilizing HIGH CPU Usage in VMware Environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568101#M10068</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for responding, only 1 indexer.&lt;/P&gt;&lt;P&gt;I have four servers&lt;/P&gt;&lt;P&gt;1A - Cluster Master&lt;/P&gt;&lt;P&gt;2A - Indexer&lt;/P&gt;&lt;P&gt;3A - Heavy Forwarder&lt;/P&gt;&lt;P&gt;4A - Search Header&lt;/P&gt;&lt;P&gt;Using ES.&lt;/P&gt;&lt;P&gt;Please let me know if you have any recommendations.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 17:03:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568101#M10068</guid>
      <dc:creator>sokngoc</dc:creator>
      <dc:date>2021-09-22T17:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Instances Utilizing HIGH CPU Usage in VMware Environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568102#M10069</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Interesting solution. I believe it might be worth a try. If it does solve the problem I will let you know.&lt;/P&gt;&lt;P&gt;However, I do see one possible fallacy to your solution. I may run into a situation where I cut the CPU cores in half and the VM continues to maximize the resource available. Then I would have to increate it back to where it was originally.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 17:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568102#M10069</guid>
      <dc:creator>sokngoc</dc:creator>
      <dc:date>2021-09-22T17:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Instances Utilizing HIGH CPU Usage in VMware Environment</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568128#M10070</link>
      <description>&lt;P class="lia-align-left"&gt;Definitely something to try. And be sure that vCores vs. sockets vs. threads are defined reasonably (what ever it means in your environment). Switching from one socket to another or use threads from two or more sockets is more expensive than using those only from one in one vm.&lt;/P&gt;&lt;P class="lia-align-left"&gt;Also remember that cleaning memory when switching content from one vm to another is quite expensive task. For that reason never overbook those resources for splunk nodes.&lt;/P&gt;&lt;P class="lia-align-left"&gt;And last thing, ensure that you have enough IOPS on all nodes (especially in indexers) at the same time. It’s not enough that one peer will get 1200+ and other 200 as all those are needed at same time when search started!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;If I recall right there are/were some VMware white papers which go through this more deeper level?&lt;/P&gt;&lt;P class="lia-align-left"&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 18:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Instances-Utilizing-HIGH-CPU-Usage-in-VMware-Environment/m-p/568128#M10070</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-09-22T18:57:15Z</dc:date>
    </item>
  </channel>
</rss>

