<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU usage on UF in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-usage-on-UF/m-p/352679#M64631</link>
    <description>&lt;P&gt;If possible, always install the forwarder on the server with the files - mounting a remote share to pull data into a UF is inefficient.&lt;BR /&gt;
Its not always possible ( I know) but UNC file shares add failure points, latency and network overhead you are better off avoiding if possible. - Probably not the direct cause of you issue, but worth considering.&lt;/P&gt;

&lt;P&gt;What version of UF/Windows? and how big are they logs. Do they break nicely? - Have you looked at your queues on the UF?&lt;/P&gt;</description>
    <pubDate>Thu, 01 Feb 2018 09:07:10 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2018-02-01T09:07:10Z</dc:date>
    <item>
      <title>High CPU usage on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-usage-on-UF/m-p/352678#M64630</link>
      <description>&lt;P&gt;We've been noticing a high CPU use on a windows splunk forwarder that only has a simple monitor statement. &lt;BR /&gt;
The following monitor is used:&lt;/P&gt;

&lt;P&gt;--inputs.conf&lt;BR /&gt;
[monitor://\server\data$\LogDir*.log]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = dataindex&lt;BR /&gt;
sourcetype = datatype&lt;/P&gt;

&lt;P&gt;With a few date.log files to monitor and the correct output to the indexers. &lt;/P&gt;

&lt;P&gt;Does anyone know what the cause might be for the high CPU? The _internal logs show nothing of interest.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 08:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-usage-on-UF/m-p/352678#M64630</guid>
      <dc:creator>mmoermans</dc:creator>
      <dc:date>2018-02-01T08:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-usage-on-UF/m-p/352679#M64631</link>
      <description>&lt;P&gt;If possible, always install the forwarder on the server with the files - mounting a remote share to pull data into a UF is inefficient.&lt;BR /&gt;
Its not always possible ( I know) but UNC file shares add failure points, latency and network overhead you are better off avoiding if possible. - Probably not the direct cause of you issue, but worth considering.&lt;/P&gt;

&lt;P&gt;What version of UF/Windows? and how big are they logs. Do they break nicely? - Have you looked at your queues on the UF?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2018 09:07:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-usage-on-UF/m-p/352679#M64631</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-02-01T09:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU usage on UF</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-usage-on-UF/m-p/352680#M64632</link>
      <description>&lt;P&gt;Hi @mmoermans,&lt;/P&gt;

&lt;P&gt;It's always recommended not to use wildcard in the monitor stanza if you really have less number of files to be monitored.&lt;/P&gt;

&lt;P&gt;Also, verify the below points-&lt;BR /&gt;
1. Number of files that are getting monitored by the command &lt;CODE&gt;./splunk list monitor&lt;/CODE&gt;.&lt;BR /&gt;
2. Size of the log files.&lt;BR /&gt;
3. Proper parsing of the log files.&lt;BR /&gt;
4. Check if any older files are being monitored and if so you can ignore those.&lt;/P&gt;

&lt;P&gt;I hope you would find something from checking the above listed points.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 06:44:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-usage-on-UF/m-p/352680#M64632</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2018-03-13T06:44:09Z</dc:date>
    </item>
  </channel>
</rss>

