<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SplunForwarder Windows strange CPU usage grow on some servers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SplunForwarder-Windows-strange-CPU-usage-grow-on-some-servers/m-p/704522#M116508</link>
    <description>&lt;P&gt;Start in the DMC to do CPU performance comparison on the various instances or try this search.&lt;/P&gt;&lt;PRE&gt;index=_introspection host=&amp;lt;replace-with-hostname&amp;gt; sourcetype=splunk_resource_usage component=PerProcess "data.pct_cpu"="*"&lt;BR /&gt;| rename data.* as *&lt;BR /&gt;| eval processes=process_type.":".process.":".args&lt;BR /&gt;| timechart span=10s max(pct_cpu) as pct_cpu by processes&lt;/PRE&gt;&lt;P&gt;This is assuming HF, you didn't specify but if it's UF there is something similar just a bit different.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2024 16:43:42 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-11-15T16:43:42Z</dc:date>
    <item>
      <title>SplunForwarder Windows strange CPU usage grow on some servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunForwarder-Windows-strange-CPU-usage-grow-on-some-servers/m-p/704493#M116498</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am facing strange issue with a Splunk Forwarder where on some servers of the same role is CPU usage 0-3% and the others are around 15%. It doesn't sound bad on the 1st hand, but it did cause us issues with deployment and such behavior is dangerous for live services if it will grow.&lt;/P&gt;&lt;P&gt;It started around 3 weeks ago with installed 9.3.0 on the Windows Server 2019 VMs with 8 CPU cores and 24GB RAM. I did update Forwarder to the 9.3.1 and the behavior is the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;For example, we have 8 servers with the same setup and apps running on, traffic to them is load balanced and very similar, log files amount and size is also very similar. 5 servers are affected, 3 not.&lt;BR /&gt;All of them have set 10 inputs, from what are 4 perfmonitors (CPU,RAM,Disk space and Web Services) and 6 inputs are checking around 40 log files.&lt;/P&gt;&lt;P&gt;Any sugestion what to check to understand what is happening?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 09:21:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunForwarder-Windows-strange-CPU-usage-grow-on-some-servers/m-p/704493#M116498</guid>
      <dc:creator>Peter95</dc:creator>
      <dc:date>2024-11-15T09:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: SplunForwarder Windows strange CPU usage grow on some servers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SplunForwarder-Windows-strange-CPU-usage-grow-on-some-servers/m-p/704522#M116508</link>
      <description>&lt;P&gt;Start in the DMC to do CPU performance comparison on the various instances or try this search.&lt;/P&gt;&lt;PRE&gt;index=_introspection host=&amp;lt;replace-with-hostname&amp;gt; sourcetype=splunk_resource_usage component=PerProcess "data.pct_cpu"="*"&lt;BR /&gt;| rename data.* as *&lt;BR /&gt;| eval processes=process_type.":".process.":".args&lt;BR /&gt;| timechart span=10s max(pct_cpu) as pct_cpu by processes&lt;/PRE&gt;&lt;P&gt;This is assuming HF, you didn't specify but if it's UF there is something similar just a bit different.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 16:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SplunForwarder-Windows-strange-CPU-usage-grow-on-some-servers/m-p/704522#M116508</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-11-15T16:43:42Z</dc:date>
    </item>
  </channel>
</rss>

