<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CPU consumption is very high in Splunk indexers in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/669832#M17927</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;There could be several reasons why indexers have high CPU%. It's really hard to make correct guess without seeing what there is happening via MC. I'm suspecting that you have MC on place? If you have, then use it and if &amp;nbsp;You haven't then it's time to setup it now.&lt;/P&gt;&lt;P&gt;Under MC there are several places where you could look in which part that issue could be:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ingesting&amp;nbsp;&lt;UL&gt;&lt;LI&gt;which pipeline&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Disk I/O etc.&lt;/LI&gt;&lt;LI&gt;searching&lt;UL&gt;&lt;LI&gt;indexer vs. sh side&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Also there must be good understanding which kind of environment you have to make guesses where that issue could be.&lt;/P&gt;&lt;P&gt;Best option will be if you could as some splunk partner/specialist or Splunk Professional services to look your environment.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 13:00:40 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-11-27T13:00:40Z</dc:date>
    <item>
      <title>CPU consumption is very high in Splunk indexers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/669801#M17926</link>
      <description>&lt;P&gt;We have 24 indexers in an indexer cluster. Recently the CPU usage is almost 100%, not on all the indexers but it fluctuates between the indexers. Under indexer clustering section, I can see the status going to "Pending" randomly between the indexers for few seconds. It is very continuous and also causes an increase in the number of fixup buckets.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have restarted the indexer servers manually where I saw high CPU load, but it did not resolve the issue. What would be the best option to fix this and the possible root cause?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions would be very helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 10:28:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/669801#M17926</guid>
      <dc:creator>shadysplunker</dc:creator>
      <dc:date>2023-11-27T10:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: CPU consumption is very high in Splunk indexers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/669832#M17927</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;There could be several reasons why indexers have high CPU%. It's really hard to make correct guess without seeing what there is happening via MC. I'm suspecting that you have MC on place? If you have, then use it and if &amp;nbsp;You haven't then it's time to setup it now.&lt;/P&gt;&lt;P&gt;Under MC there are several places where you could look in which part that issue could be:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ingesting&amp;nbsp;&lt;UL&gt;&lt;LI&gt;which pipeline&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Disk I/O etc.&lt;/LI&gt;&lt;LI&gt;searching&lt;UL&gt;&lt;LI&gt;indexer vs. sh side&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Also there must be good understanding which kind of environment you have to make guesses where that issue could be.&lt;/P&gt;&lt;P&gt;Best option will be if you could as some splunk partner/specialist or Splunk Professional services to look your environment.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/669832#M17927</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-11-27T13:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: CPU consumption is very high in Splunk indexers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/669970#M17935</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I noticed that ingestion latency health check is turning yellow for indexers. Even there is a delay in searching for the data. The index queues shows blocked while checking the internal logs of heavy forwarders.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could performing a rolling restart of indexers help since it has been a very long time now doing that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 07:28:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/669970#M17935</guid>
      <dc:creator>shadysplunker</dc:creator>
      <dc:date>2023-11-28T07:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: CPU consumption is very high in Splunk indexers</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/670005#M17940</link>
      <description>&lt;P&gt;Without any concrete data it's just fortune telling.&lt;/P&gt;&lt;P&gt;Check processes, check i/o saturation, check memory usage. Verify if it's even Splunk that's causing cpu hogging.&lt;/P&gt;&lt;P&gt;Restarting processes blindly will not help much probably without addressing the underlying cause.&lt;/P&gt;&lt;P&gt;Has anything been changed recently? Upgraded?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 11:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/CPU-consumption-is-very-high-in-Splunk-indexers/m-p/670005#M17940</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-28T11:29:07Z</dc:date>
    </item>
  </channel>
</rss>

