<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are we seeing high memory usage with a Splunk 6.2.3 forwarder installed on a Windows server? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-seeing-high-memory-usage-with-a-Splunk-6-2-3/m-p/269388#M51725</link>
    <description>&lt;P&gt;The amount of memory that a Splunk forwarder uses is directly related to the number of files that the forwarder is monitoring.&lt;/P&gt;

&lt;P&gt;How many files is the forwarder monitoring? If you are not sure, log on the the machine and run&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk list monitor
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You may see that you are monitoring &lt;EM&gt;many&lt;/EM&gt; files, including inactive files. The problem is that Splunk cannot be sure those files are inactive; it will continue to keep them in its list of files to monitor. If you can refine the stanzas in inputs.conf to monitor less - or remove the inactive files from the path that Splunk is monitoring - you will probably see an immediate reduction in the memory and CPU consumption. (You will have to restart the forwarder after making these changes.)&lt;/P&gt;

&lt;P&gt;Of course, this is just a guess, based on not much information...&lt;/P&gt;</description>
    <pubDate>Thu, 10 Dec 2015 20:23:18 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2015-12-10T20:23:18Z</dc:date>
    <item>
      <title>Why are we seeing high memory usage with a Splunk 6.2.3 forwarder installed on a Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-seeing-high-memory-usage-with-a-Splunk-6-2-3/m-p/269387#M51724</link>
      <description>&lt;P&gt;We are currently having an issue with Splunk forwarder installed on a Windows server. It takes up a lot of memory utilization. &lt;/P&gt;

&lt;P&gt;Any suggestion how to fix this? We are running Splunk 6.2.3. Help help. Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2015 13:56:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-seeing-high-memory-usage-with-a-Splunk-6-2-3/m-p/269387#M51724</guid>
      <dc:creator>mattkun</dc:creator>
      <dc:date>2015-12-10T13:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why are we seeing high memory usage with a Splunk 6.2.3 forwarder installed on a Windows server?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-seeing-high-memory-usage-with-a-Splunk-6-2-3/m-p/269388#M51725</link>
      <description>&lt;P&gt;The amount of memory that a Splunk forwarder uses is directly related to the number of files that the forwarder is monitoring.&lt;/P&gt;

&lt;P&gt;How many files is the forwarder monitoring? If you are not sure, log on the the machine and run&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk list monitor
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You may see that you are monitoring &lt;EM&gt;many&lt;/EM&gt; files, including inactive files. The problem is that Splunk cannot be sure those files are inactive; it will continue to keep them in its list of files to monitor. If you can refine the stanzas in inputs.conf to monitor less - or remove the inactive files from the path that Splunk is monitoring - you will probably see an immediate reduction in the memory and CPU consumption. (You will have to restart the forwarder after making these changes.)&lt;/P&gt;

&lt;P&gt;Of course, this is just a guess, based on not much information...&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2015 20:23:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-we-seeing-high-memory-usage-with-a-Splunk-6-2-3/m-p/269388#M51725</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2015-12-10T20:23:18Z</dc:date>
    </item>
  </channel>
</rss>

