<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk enterprise in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591190#M11965</link>
    <description>&lt;P&gt;OK. If your device counters show high volume of traffic but you don't see much traffic on the machine, there is definitely something wrong in your setup but it's way beyond scope of this forum.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 06:44:13 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-03-29T06:44:13Z</dc:date>
    <item>
      <title>How to resolve when the memory spike occurs in splunk indexer?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591071#M11939</link>
      <description>&lt;P&gt;How to resolve memory spike ?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 11:39:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591071#M11939</guid>
      <dc:creator>human96</dc:creator>
      <dc:date>2022-03-29T11:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591077#M11941</link>
      <description>&lt;P&gt;Unless you hit a very strange bug, events shouldn't suddenly be indexed with "wrong contents".&lt;/P&gt;&lt;P&gt;They queues could get stuck and your data could be delayed or even lost but it shouldn't get modified for no reason.&lt;/P&gt;&lt;P&gt;What do you mean by wrong contents?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 12:03:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591077#M11941</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-28T12:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when the memory spike occurs in splunk indexer, the data is registered with the wrong contents</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591108#M11951</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243040"&gt;@human96&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you probably should throw more content to this context to get better answers.&amp;nbsp; what is generating the source data seems like its a scripted input you probably need to check the script&amp;nbsp;&lt;/P&gt;&lt;P&gt;as highlighted by&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp; data never gets modified on the fly its always on the source or the dependencies which create the sources which brings the change in existing data ingestion flow&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 15:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591108#M11951</guid>
      <dc:creator>venky1544</dc:creator>
      <dc:date>2022-03-28T15:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591167#M11960</link>
      <description>&lt;P&gt;&lt;SPAN&gt;a value of nearly 90 times of the normal value is displaying. This is only happening when a&amp;nbsp;memory spike in the&amp;nbsp; indexer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;can you tell me why it's happening ? and what could be the possible solution ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 05:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591167#M11960</guid>
      <dc:creator>human96</dc:creator>
      <dc:date>2022-03-31T05:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when the memory spike occurs in splunk indexer, the data is registered with the wrong contents</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591169#M11961</link>
      <description>&lt;P&gt;&lt;SPAN&gt;i'm getting a strange number of bytes (IF-MIB:: ifHCInOctets, IF-MIB:: ifHCOutOctets) received/sent on the device interface.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;a value of nearly 90 times of the normal value is displaying. This is only happening when a&amp;nbsp;memory spike in the&amp;nbsp; indexer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;can you tell me why it's happening ? and what could be the possible solution ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 04:56:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591169#M11961</guid>
      <dc:creator>human96</dc:creator>
      <dc:date>2022-03-29T04:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591188#M11963</link>
      <description>&lt;P&gt;Hard to diagnose anything based on such limited information but I'd hazard a guess that it's the other way around - you're getting sudden spike of either a huge load of data to be processed, huge amount of searches requested or even simply a huge number of general "random" requests from vulnerability manager or something like that. And the requests cause your splunk to build up resource usage. Not the other way around.&lt;/P&gt;&lt;P&gt;But it's up to you to find what this traffic is.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 06:23:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591188#M11963</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-29T06:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591189#M11964</link>
      <description>&lt;P&gt;&lt;SPAN&gt;i investigated and found out no large amount of traffic inflow in that specific time range.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and one more thing those are Derive&amp;nbsp;&amp;nbsp;type of data and was imported in HEC.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 06:28:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591189#M11964</guid>
      <dc:creator>human96</dc:creator>
      <dc:date>2022-03-29T06:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: splunk enterprise</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591190#M11965</link>
      <description>&lt;P&gt;OK. If your device counters show high volume of traffic but you don't see much traffic on the machine, there is definitely something wrong in your setup but it's way beyond scope of this forum.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 06:44:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-resolve-when-the-memory-spike-occurs-in-splunk-indexer/m-p/591190#M11965</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-29T06:44:13Z</dc:date>
    </item>
  </channel>
</rss>

