<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Will upgrading our Splunk indexer server with high performance hardware and dividing the indexer with multiple servers solve our high CPU performance issue? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150260#M30541</link>
    <description>&lt;P&gt;What does your current topology look like?&lt;BR /&gt;
How many transforms (index time extractions) be performed?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2015 21:52:28 GMT</pubDate>
    <dc:creator>bmacias84</dc:creator>
    <dc:date>2015-07-30T21:52:28Z</dc:date>
    <item>
      <title>Will upgrading our Splunk indexer server with high performance hardware and dividing the indexer with multiple servers solve our high CPU performance issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150259#M30540</link>
      <description>&lt;P&gt;Hi Team, &lt;/P&gt;

&lt;P&gt;Currently we are facing a high CPU utilization issue on our indexer because of Splunk's high usage. To resolve this we are planning to upgrade our server in two ways.&lt;/P&gt;

&lt;P&gt;1)  Upgrade same server with high performance hardware.&lt;BR /&gt;
2)  Divide indexer with multiple servers.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 21:04:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150259#M30540</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2015-07-30T21:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Will upgrading our Splunk indexer server with high performance hardware and dividing the indexer with multiple servers solve our high CPU performance issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150260#M30541</link>
      <description>&lt;P&gt;What does your current topology look like?&lt;BR /&gt;
How many transforms (index time extractions) be performed?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 21:52:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150260#M30541</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2015-07-30T21:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Will upgrading our Splunk indexer server with high performance hardware and dividing the indexer with multiple servers solve our high CPU performance issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150261#M30542</link>
      <description>&lt;P&gt;I have 1 SH &amp;amp; 1 indexer with 58 forwarders. From Monday size of data coming to indexer has increased upto 20 percent due to some new changes. &lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2015 00:28:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150261#M30542</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2015-07-31T00:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Will upgrading our Splunk indexer server with high performance hardware and dividing the indexer with multiple servers solve our high CPU performance issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150262#M30543</link>
      <description>&lt;P&gt;Seem like a relatively small deployment.  Whats your indexing volume?  What Splunk apps are you using?  Was your indexer ever a search head (All-in-one deployment)? Have you configured &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/Admin/ConfiguretheMonitoringConsole"&gt;the distributed management console&lt;/A&gt;, it has a lot of good diagnostic information.  I would look at CPU Usage per Splunk Processor.   More indexers wont hurt, but adding hardware before you know what your bottle neck is won't necessarily fix your issue.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2015 16:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150262#M30543</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2015-07-31T16:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Will upgrading our Splunk indexer server with high performance hardware and dividing the indexer with multiple servers solve our high CPU performance issue?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150263#M30544</link>
      <description>&lt;P&gt;You don't have a very complex setup as bmacias84 mentioned... and yet you mention a 20% increase in volume. Was that 150GB per day and it's now gone beyond to 180? Anything less than that might be helped by adding an indexer but it will just be diluting the problem not solving it.&lt;/P&gt;

&lt;P&gt;You mention high performance hardware (mem? CPU? etc...)&lt;/P&gt;

&lt;P&gt;Unnaturally High CPU usage can = something like bad disk. Indexer IO is quite intensive... so if it's hammering around trying to manage buckets, you're going to see CPU go through the roof. And if there are bad spots and good spots... it won't be consistent. This is a great reason to request support as there are many tools they can use to help you narrow down what might be the problem.&lt;BR /&gt;
Check out this page here&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/Troubleshooting/Collectpstacks"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.4/Troubleshooting/Collectpstacks&lt;/A&gt;&lt;BR /&gt;
Create a diag of each component.&lt;BR /&gt;
&lt;CODE&gt;$SPLUNK_HOME/bin/diag&lt;/CODE&gt;&lt;BR /&gt;
and open a support ticket. Upload the diag and results of pstack (or if on windows follow info on collecting stack bits)&lt;/P&gt;</description>
      <pubDate>Sun, 02 Aug 2015 23:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Will-upgrading-our-Splunk-indexer-server-with-high-performance/m-p/150263#M30544</guid>
      <dc:creator>rsennett_splunk</dc:creator>
      <dc:date>2015-08-02T23:46:11Z</dc:date>
    </item>
  </channel>
</rss>

