<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Universal Forwarder using 2GB of RAM? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179559#M36025</link>
    <description>&lt;P&gt;I've seen this before as well. Size of usage directly correlates with number of files monitored. The more files, the more memory. You may want to remove the files that are &amp;gt; 6 months old, I mean, you have Splunk to store those contents, no? why keep the raw data around? Or if you have that many active files, good luck &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jan 2015 18:27:22 GMT</pubDate>
    <dc:creator>alacercogitatus</dc:creator>
    <dc:date>2015-01-08T18:27:22Z</dc:date>
    <item>
      <title>Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179558#M36024</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;

&lt;P&gt;I've just installed the Universal Forwarder on my NAS server(Windows Server 2008 R2) and I have configured it to read files from a directory.&lt;/P&gt;

&lt;P&gt;The directory it is reading from contains 209,000 800byte files dating from November 2013 to now. I told the forwarder to give me the last 6 months.&lt;/P&gt;

&lt;P&gt;I noticed that during forwarding, the Universal Forwarder was using 2,072,XXX kilobytes. I assumed that this was just because it was forwarding files containing over 2.5million events.&lt;/P&gt;

&lt;P&gt;Once forwarding was complete and my indexer had the complete set of data from this forwarder, I expected the RAM utilization to drop, but it hasn't. &lt;/P&gt;

&lt;P&gt;Splunk seems to be stuck at just under 2GB, I've restarted it many times and no luck, it just climbs straight back up to 2GB and stays there.&lt;/P&gt;

&lt;P&gt;If I disable the app that looks into the directory that has this large amount of files, the forwarder only uses 50Mb.&lt;/P&gt;

&lt;P&gt;The question is: how can I keep this RAM utilization down? I need that directory monitored.&lt;/P&gt;

&lt;P&gt;Couple of things to note:&lt;/P&gt;

&lt;P&gt;The inputs.conf is using &lt;CODE&gt;crcSalt=&lt;/CODE&gt; and &lt;CODE&gt;initCrcLength=1000&lt;/CODE&gt; - I think this may be relevant but the forwarding will not work without it.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 18:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179558#M36024</guid>
      <dc:creator>kendrickt</dc:creator>
      <dc:date>2015-01-08T18:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179559#M36025</link>
      <description>&lt;P&gt;I've seen this before as well. Size of usage directly correlates with number of files monitored. The more files, the more memory. You may want to remove the files that are &amp;gt; 6 months old, I mean, you have Splunk to store those contents, no? why keep the raw data around? Or if you have that many active files, good luck &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 18:27:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179559#M36025</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-01-08T18:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179560#M36026</link>
      <description>&lt;P&gt;Can't seem to add a comment to your answer, alacerogitatus, so I'll comment here.&lt;/P&gt;

&lt;P&gt;This is a production system I'm dealing with - the files in this directory are used by atleast 2 other applications.&lt;/P&gt;

&lt;P&gt;Yes - The files should be tidied up and perhaps there shouldn't be that many in a single directory.&lt;/P&gt;

&lt;P&gt;No - It's not something I would be easily authorised to do, I could tell Splunk to &lt;CODE&gt;ignoreOlderThan=1d&lt;/CODE&gt; but I think the problem will still exist down the line.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 18:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179560#M36026</guid>
      <dc:creator>kendrickt</dc:creator>
      <dc:date>2015-01-08T18:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179561#M36027</link>
      <description>&lt;P&gt;I don't think its "Files per Directory" more of "Total Files".  I would try the ignoreOlderThan Flag, as then if the timestamps aren't updated, it shouldn't look at it at all.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 18:58:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179561#M36027</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-01-08T18:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179562#M36028</link>
      <description>&lt;P&gt;I just added &lt;CODE&gt;ignoreOlderThan=3h&lt;/CODE&gt; to the inputs.conf&lt;/P&gt;

&lt;P&gt;RAM Utilisation is still at 850Mb. There has to be another solution...&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 19:42:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179562#M36028</guid>
      <dc:creator>kendrickt</dc:creator>
      <dc:date>2015-01-08T19:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179563#M36029</link>
      <description>&lt;P&gt;How many files are newer than 3h old? &lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 19:49:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179563#M36029</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-01-08T19:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179564#M36030</link>
      <description>&lt;P&gt;1 every 5 minutes, so approximate 36 800byte files. Shouldn't take 850mb of RAM?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 19:53:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179564#M36030</guid>
      <dc:creator>kendrickt</dc:creator>
      <dc:date>2015-01-08T19:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179565#M36031</link>
      <description>&lt;P&gt;Goto your Task Manager, and in Processes, add the column "Handles". How many for splunkd.exe ?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2015 19:55:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179565#M36031</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-01-08T19:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder using 2GB of RAM?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179566#M36032</link>
      <description>&lt;P&gt;I've disabled the forwarder for now - I can't re-enable it until I enter a new change window after the weekend.&lt;/P&gt;

&lt;P&gt;Thanks for the suggestions so far. I will update this thread when I have more information.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2015 13:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-using-2GB-of-RAM/m-p/179566#M36032</guid>
      <dc:creator>kendrickt</dc:creator>
      <dc:date>2015-01-09T13:36:57Z</dc:date>
    </item>
  </channel>
</rss>

