<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data Onboarding CPU consumption 150% system stuck. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755957#M119927</link>
    <description>&lt;P&gt;I am on-boarding data from 6 different locations the data flow is&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk Forwarder&amp;nbsp; ------&amp;gt; DMZ Server (Intermediate Forwarder) -----------&amp;gt; Indexer&lt;/P&gt;&lt;P&gt;Initially I was getting aggqueue, parsingqueue, indexqueue and typingqueue blocked.&lt;/P&gt;&lt;P&gt;I had to set all this queue sizes in server.conf to maxSize = 2048MB,.&lt;/P&gt;&lt;P&gt;In limits.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;[thruput]&lt;/P&gt;&lt;P&gt;maxKBps = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This worked for 5 locations. But for 1 location CPU consumption became very high which led to system freeze.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, is there a way to onboard data without using much resources.&lt;/P&gt;&lt;P&gt;please help&lt;/P&gt;</description>
    <pubDate>Fri, 28 Nov 2025 12:57:56 GMT</pubDate>
    <dc:creator>kgiri253</dc:creator>
    <dc:date>2025-11-28T12:57:56Z</dc:date>
    <item>
      <title>Data Onboarding CPU consumption 150% system stuck.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755957#M119927</link>
      <description>&lt;P&gt;I am on-boarding data from 6 different locations the data flow is&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk Forwarder&amp;nbsp; ------&amp;gt; DMZ Server (Intermediate Forwarder) -----------&amp;gt; Indexer&lt;/P&gt;&lt;P&gt;Initially I was getting aggqueue, parsingqueue, indexqueue and typingqueue blocked.&lt;/P&gt;&lt;P&gt;I had to set all this queue sizes in server.conf to maxSize = 2048MB,.&lt;/P&gt;&lt;P&gt;In limits.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;[thruput]&lt;/P&gt;&lt;P&gt;maxKBps = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This worked for 5 locations. But for 1 location CPU consumption became very high which led to system freeze.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, is there a way to onboard data without using much resources.&lt;/P&gt;&lt;P&gt;please help&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 12:57:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755957#M119927</guid>
      <dc:creator>kgiri253</dc:creator>
      <dc:date>2025-11-28T12:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding CPU consumption 150% system stuck.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755961#M119928</link>
      <description>&lt;P&gt;We need some more information.&lt;/P&gt;&lt;P&gt;Are all location using the Splunk Universal Forwarder?&amp;nbsp; If not, that is what they should be using.&lt;/P&gt;&lt;P&gt;Is the Intermediate Forwarder a heavy forwarder or universal forwarder?&lt;/P&gt;&lt;P&gt;Where did the queue blocking occur?&lt;/P&gt;&lt;P&gt;Where did you make the changes to server.conf and limits.conf?&amp;nbsp; Did you restart each Splunk instance after making the changes?&lt;/P&gt;&lt;P&gt;What inputs are enabled on the location with high CPU usage?&amp;nbsp; Which TAs/apps are installed there?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Nov 2025 13:02:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755961#M119928</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-11-28T13:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding CPU consumption 150% system stuck.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755975#M119931</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;hinted - it might depend on the type of inputs you're using and amount of data to be ingested. You might, for example, have a case where you have a lot of backlog to be ingested and the UF will cause high load untill it catches up to the current events and then it will ease. For some inputs you might be able to just start at current events and ignore the older ones. It's hard to say without knowing your full setup.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2025 13:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755975#M119931</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-11-29T13:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding CPU consumption 150% system stuck.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755983#M119932</link>
      <description>&lt;P&gt;Thanks for your answer, we had a big backlog of data to be ingested that's why more resources were getting consumed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 08:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/755983#M119932</guid>
      <dc:creator>anish</dc:creator>
      <dc:date>2025-12-01T08:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding CPU consumption 150% system stuck.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/756286#M119959</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249277"&gt;@kgiri253&lt;/a&gt;&amp;nbsp;, I was never a great fan of minimal throughput from the forwarders and tiny memory buffers on the Splunk servers. In my mind, these strict low quotas lead to issues, like yours in many cases.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 17:11:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/756286#M119959</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2025-12-08T17:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Data Onboarding CPU consumption 150% system stuck.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/756295#M119961</link>
      <description>&lt;P&gt;Making buffers too big and removing thruput limits may not yield great results. Try flushing several gigabytes worth of buffers on forwarder's close. Try getting sudden peak of data when a site with several hundreds of endpoints comes back from a site network outage...&lt;/P&gt;&lt;P&gt;There are pros and cons to everything &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 21:34:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-Onboarding-CPU-consumption-150-system-stuck/m-p/756295#M119961</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-12-08T21:34:39Z</dc:date>
    </item>
  </channel>
</rss>

