<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU Usage on Splunk Indexers in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/561185#M92707</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/126376"&gt;@alexspunkshell&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;At first, some quick questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what's your hardware configuration (CPUs and RAM)?&lt;/LI&gt;&lt;LI&gt;did you used the recommended hardware references?&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/Capacity/Referencehardware" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/Capacity/Referencehardware&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;which apps are you using? Enterprise Security, Security Essentials, etc...&lt;/LI&gt;&lt;LI&gt;what storage are you using? (Splunk recommends at least 800 IOPS).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you're using a correct HW configuration and you haven't special requirements from some App, you can see if there are some heavy scheduled searches that make your system busy.&lt;/P&gt;&lt;P&gt;E.g., if you're using Real Time Searches, you tale a CPU for each search you're sunning, so if you have some real time search with one or two subsearches you're filling your system.&lt;/P&gt;&lt;P&gt;Then, are you usung searches with transaction or join commands? they are very expensive for resources.&lt;/P&gt;&lt;P&gt;You can check the running searches, as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; said, using the Monitoring Console [Settings -- Resource Usage -- CPU Usage: Instance].&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jul 2021 12:33:47 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-07-28T12:33:47Z</dc:date>
    <item>
      <title>High CPU Usage on Splunk Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/511544#M86874</link>
      <description>&lt;P&gt;Frequently i am receiving high CPU Usage alerts with over 99% on all 3 indexers.&lt;/P&gt;&lt;P&gt;I am unable to search any query. It shows waiting for quequed job to start.&lt;/P&gt;&lt;P&gt;Please help me here. How to check the issue and resolve it.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 15:07:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/511544#M86874</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2020-07-29T15:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on Splunk Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/511595#M86876</link>
      <description>Check the Monitoring Console (Settings-&amp;gt;Monitoring Console-&amp;gt;Indexing-&amp;gt;Performance-&amp;gt;Indexing Performance: Advanced) for insights.</description>
      <pubDate>Wed, 29 Jul 2020 17:37:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/511595#M86876</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-29T17:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on Splunk Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/512375#M86926</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Thanks for your reply.&lt;/P&gt;&lt;P&gt;Checked the&amp;nbsp;&lt;SPAN&gt;Monitoring Console (Settings-&amp;gt;Monitoring Console-&amp;gt;Indexing-&amp;gt;Performance-&amp;gt;Indexing Performance: Advanced)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But its not showing any details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Showing no results found. Any other alternative ways to get a solution?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 13:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/512375#M86926</guid>
      <dc:creator>alexspunkshell</dc:creator>
      <dc:date>2020-08-04T13:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on Splunk Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/512382#M86927</link>
      <description>"No results found" means the MC is not configured. Make sure you're signed in to the right Splunk instance and that the MC is set up.</description>
      <pubDate>Tue, 04 Aug 2020 14:08:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/512382#M86927</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-04T14:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on Splunk Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/512710#M86946</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;In order to find the root cause, in your Indexers, go to Monitoring console -&amp;gt; Resource usage -&amp;gt; Resource usage: Instance.&lt;/P&gt;&lt;P&gt;Under the snapshots section, you'll find two very important graphs. Physical memory usage by process class and CPU Usage by process class.&lt;/P&gt;&lt;P&gt;You'd want to look at the CPU usage graphs and see what's causing the hogging of CPU utilisation. If it says Search, that means you have to look at people running resource intensive searches in your environment. For that, you'd want to go to Search -&amp;gt; Search Activity: Instance and check everything out from there.&lt;/P&gt;&lt;P&gt;You can always create alerts off the audit data to find violators, who are running long running searches, or too many searches etc. If it's not a search issue, please contact Splunk support, as it maybe a case of memory leakage.&lt;/P&gt;&lt;P&gt;Here's the article that you can also go through for this:&lt;/P&gt;&lt;P&gt;&lt;A href="#https://docs.splunk.com/Documentation/Splunk/8.0.5/DMC/ResourceusageCPU" target="_self"&gt;Resouce Usage CPU - Splunk Docs&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;S.&lt;/P&gt;&lt;P&gt;Note: If this helped, please mark it as an accepted answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2020 10:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/512710#M86946</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2020-08-06T10:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on Splunk Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/561182#M92706</link>
      <description>&lt;P&gt;We also had high CPU usage on our indexers in a test enviroment and query's took a very long (45 min)time.&lt;/P&gt;&lt;P&gt;In the monitoring of the servers we noticed that the cpu ready time was between 1 and 5 Ms. The usage of the server was 100%&amp;nbsp;&lt;/P&gt;&lt;P&gt;The server had 8 Vcpu's.&lt;/P&gt;&lt;P&gt;By reducing the number of vcpu's to 2 vcpu;s per server the cpu ready time reduced.&lt;/P&gt;&lt;P&gt;This gave a large peformance boost on the&amp;nbsp; indexers query's time was reduced for the same query to 5 Min&lt;/P&gt;&lt;P&gt;So my advice if you are running in a virtualized enviroment play with the number of vcpu's to get the optimal peformance. I know the say minimum 16 vCpu but if you have high ready times it is worth to try.&lt;/P&gt;&lt;P&gt;Look at the number of MHZ the server Uses and divide this by the speed of your cores en set this number of vcpu's to begin with.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 12:17:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/561182#M92706</guid>
      <dc:creator>bakkre</dc:creator>
      <dc:date>2021-07-28T12:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Usage on Splunk Indexers</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/561185#M92707</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/126376"&gt;@alexspunkshell&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;At first, some quick questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what's your hardware configuration (CPUs and RAM)?&lt;/LI&gt;&lt;LI&gt;did you used the recommended hardware references?&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.1/Capacity/Referencehardware" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.1/Capacity/Referencehardware&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;which apps are you using? Enterprise Security, Security Essentials, etc...&lt;/LI&gt;&lt;LI&gt;what storage are you using? (Splunk recommends at least 800 IOPS).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you're using a correct HW configuration and you haven't special requirements from some App, you can see if there are some heavy scheduled searches that make your system busy.&lt;/P&gt;&lt;P&gt;E.g., if you're using Real Time Searches, you tale a CPU for each search you're sunning, so if you have some real time search with one or two subsearches you're filling your system.&lt;/P&gt;&lt;P&gt;Then, are you usung searches with transaction or join commands? they are very expensive for resources.&lt;/P&gt;&lt;P&gt;You can check the running searches, as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; said, using the Monitoring Console [Settings -- Resource Usage -- CPU Usage: Instance].&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 12:33:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/High-CPU-Usage-on-Splunk-Indexers/m-p/561185#M92707</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-28T12:33:47Z</dc:date>
    </item>
  </channel>
</rss>

