<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logging thousend files via Splunk Forwarder causes high CPU load in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405810#M72010</link>
    <description>&lt;P&gt;we use the newst one 7.1.2.X&lt;/P&gt;</description>
    <pubDate>Mon, 13 Aug 2018 07:39:52 GMT</pubDate>
    <dc:creator>tfechner</dc:creator>
    <dc:date>2018-08-13T07:39:52Z</dc:date>
    <item>
      <title>Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405803#M72003</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;we have a oracle logging directory  with thousend .aud files for logging to Splunk.&lt;BR /&gt;
Each day over 700 new files will be created. &lt;BR /&gt;
We experience a heavy workload on the system caused by the splunkd process.&lt;/P&gt;

&lt;P&gt;We think splunkd monitores ALL files and after some weeks a hugh bunch of filemonitoring threads are occuping the CPU.&lt;/P&gt;

&lt;P&gt;How can we tell splunk not to monitor already indexed files and only have a look on new created. The closed file will never be changed anymore.&lt;/P&gt;

&lt;P&gt;Our inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///oracle/Q*/trace/audit/*.aud]
sourcetype=oracle:audit:text
whitelist = \w.+.aud
ignoreOlderThan=7d
index=oracle_sap
disabled = false
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 Aug 2018 13:59:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405803#M72003</guid>
      <dc:creator>tfechner</dc:creator>
      <dc:date>2018-08-10T13:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405804#M72004</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;How are your new files named? Any thing to differentiate new and old. &lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 14:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405804#M72004</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-10T14:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405805#M72005</link>
      <description>&lt;P&gt;I think you have to create your own script to delete/move/rename the indexed files.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 14:43:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405805#M72005</guid>
      <dc:creator>amiftah</dc:creator>
      <dc:date>2018-08-10T14:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405806#M72006</link>
      <description>&lt;P&gt;fielname_structure:&lt;BR /&gt;
AppID_OracleID_timestamp.aud&lt;BR /&gt;
with:&lt;BR /&gt;
appid= P56&lt;BR /&gt;
OracleID: 53457673 &lt;BR /&gt;
time: 2018073134756825434785&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:53:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405806#M72006</guid>
      <dc:creator>tfechner</dc:creator>
      <dc:date>2020-09-29T20:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405807#M72007</link>
      <description>&lt;P&gt;fielname_structure:&lt;BR /&gt;
AppID_OracleID_timestamp.aud&lt;BR /&gt;
with:&lt;BR /&gt;
appid= P56&lt;BR /&gt;
OracleID: 53457673 &lt;BR /&gt;
time: 2018073134756825434785&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405807#M72007</guid>
      <dc:creator>tfechner</dc:creator>
      <dc:date>2020-09-29T20:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405808#M72008</link>
      <description>&lt;P&gt;The naming doesn't seem to be helpful. Since new files are created every day, decrease &lt;CODE&gt;ignoreOlderThan&lt;/CODE&gt; to 2 or 3 days. This can reduce load.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 15:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405808#M72008</guid>
      <dc:creator>sudosplunk</dc:creator>
      <dc:date>2018-08-10T15:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405809#M72009</link>
      <description>&lt;P&gt;What's the forwarder version? - &lt;A href="https://answers.splunk.com/answers/435993/universal-forwarder-using-high-cpu.html"&gt;Universal Forwarder Using High CPU?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 22:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405809#M72009</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-08-11T22:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Logging thousend files via Splunk Forwarder causes high CPU load</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405810#M72010</link>
      <description>&lt;P&gt;we use the newst one 7.1.2.X&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 07:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Logging-thousend-files-via-Splunk-Forwarder-causes-high-CPU-load/m-p/405810#M72010</guid>
      <dc:creator>tfechner</dc:creator>
      <dc:date>2018-08-13T07:39:52Z</dc:date>
    </item>
  </channel>
</rss>

