<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Memory usage increase in V5? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19169#M338</link>
    <description>&lt;P&gt;I upgraded Splunk 4.3.4 to v5 and have a handful of event sources. Apart from restarting the service, the performance hasn't changed a bit. Response time is just the same as well.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Nov 2012 10:38:31 GMT</pubDate>
    <dc:creator>miteshvohra</dc:creator>
    <dc:date>2012-11-07T10:38:31Z</dc:date>
    <item>
      <title>Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19163#M332</link>
      <description>&lt;P&gt;Upgraded from Splunk 4.3.4 on Windows server to V5. Since the upgrade the server is at a crawl and is often timing out trying to connect to the web interface. Was there a big increase in memory needs that I missed?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 19:12:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19163#M332</guid>
      <dc:creator>larryrosen</dc:creator>
      <dc:date>2012-10-31T19:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19164#M333</link>
      <description>&lt;P&gt;yes splunk 5.0 uses more ressources :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;more file descriptors are used in general&lt;/LI&gt;
&lt;LI&gt;the clustering replication  uses more disk i/o and generate  network traffic, and require more storage&lt;/LI&gt;
&lt;LI&gt;the transparent summarization implies ongoing backend searches to generate them, and add some volume to the buckets,&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;But in our case, it may also be a configuration issue, (deployment server, apps, backfill ...)&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 19:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19164#M333</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-10-31T19:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19165#M334</link>
      <description>&lt;P&gt;we have had to reboot our V5 indexer twice in the last 24 hours.  System crawls to a halt, and looking at the stats, the memory grows in a straight line until all is consumed, and the system effectively stops.  We are only taking syslogs from 6 firewalls, and event logs from two windows boxes.  The indexer has 8Gb of memory available.  It looks like it might be a memory leak.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 23:02:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19165#M334</guid>
      <dc:creator>cccrossw</dc:creator>
      <dc:date>2012-10-31T23:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19166#M335</link>
      <description>&lt;P&gt;I have to agree something is causing rapid loss of memory (and not my turning 50 this December!).&lt;/P&gt;

&lt;P&gt;We are seeing the same thing since 5.0&lt;/P&gt;

&lt;P&gt;4gb system, not that many inputs.... Was running smooth on 4.3.4 but since upgrade exhausted all memory and froze.... Added 2gb extra RAM and while the server started up fine, within 1/2 hour all the ram had been consumed and it was unusable again.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 12:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19166#M335</guid>
      <dc:creator>larryrosen</dc:creator>
      <dc:date>2012-11-02T12:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19167#M336</link>
      <description>&lt;P&gt;To investigate a memory leak, &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;please install the SOS app (or the TA-sos) on the indexer, &lt;/LI&gt;
&lt;LI&gt;turn on the scripted inputs ps-sos.sh (on linux) or ps-sos.ps1 (powershell on windows, read the README for configuration instruction).&lt;/LI&gt;
&lt;LI&gt;let it run several hours to one day, after a restart to collect the memory/cpu usage.&lt;/LI&gt;
&lt;LI&gt;go to the sos dashboard for resource usage, and check which splunk processes are leaking memory.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Then create a support case and attach diag and screenshots, also precise if you turned on special features of 5.0 (like replication or search acceleration)&lt;/P&gt;</description>
      <pubDate>Fri, 02 Nov 2012 15:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19167#M336</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-11-02T15:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19168#M337</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I also see a steady increase of memory usage on our search head since the upgrade to v5.0. The indexers and universal forwarders are running fine, though.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 10:17:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19168#M337</guid>
      <dc:creator>mschroeder</dc:creator>
      <dc:date>2012-11-07T10:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19169#M338</link>
      <description>&lt;P&gt;I upgraded Splunk 4.3.4 to v5 and have a handful of event sources. Apart from restarting the service, the performance hasn't changed a bit. Response time is just the same as well.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 10:38:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19169#M338</guid>
      <dc:creator>miteshvohra</dc:creator>
      <dc:date>2012-11-07T10:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19170#M339</link>
      <description>&lt;P&gt;What types of input do you have, and are you running any special apps? You should probably run a "splunk diag" and include the diag file to the support case.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 12:34:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19170#M339</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-11-07T12:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19171#M340</link>
      <description>&lt;P&gt;I am seeing this same issue on one of two indexers after the 5.0 upgrade.&lt;BR /&gt;
Memory is leaking on one of them (SplunkD process) until fully consumed.&lt;/P&gt;

&lt;P&gt;There are some configuration differences between the two. I will troubleshoot this issue some more.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 15:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19171#M340</guid>
      <dc:creator>jeklof</dc:creator>
      <dc:date>2012-11-07T15:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19172#M341</link>
      <description>&lt;P&gt;I'm seeing Similar issues on our Heavy Forwarders. I'll follow the above suggestions and see if that sheds any light!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2012 17:28:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19172#M341</guid>
      <dc:creator>paxindustria</dc:creator>
      <dc:date>2012-11-07T17:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19173#M342</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;We have determined that in Splunk 5.0, active UDP inputs cause the main splunkd process to leak memory. The rate of this memory leak appears to be proportional to the rate of data that is being received on the UDP input(s). For that reason, it is possible for a very active UDP input to cause splunkd to eventually exhaust all available memory on the host.&lt;/P&gt;

&lt;P&gt;The bug that references this behavior is SPL-58075 and has been added to the &lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/ReleaseNotes/Knownissues#Data_input_issues"&gt;list of known issues for Splunk 5.0&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;We are actively working towards the release of a fix to this issue in the next few days.&lt;/P&gt;

&lt;P&gt;In the meantime, there are four possible work-arounds that we can propose:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;Install a 4.3.4 universal forwarder on the same machine that is currently receiving the UDP traffic and migrate the UDP inputs to that instance. The universal forwarder should be configured to send all incoming data to the indexer on the same host.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Where possible customers should switch from sending data via UDP to sending via TCP as it helps to reduce potential data loss and is more in line with best practices for sending network data to Splunk. Be advised that this input removes syslogd event augmentation (e.g. timestamp and hostname pre-pending)&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Schedule a restart of the impacted instance(s) at regular intervals to prevent memory exhaustion. This solution is not strongly recommended as it can introduce data loss and kick users out of the system.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Disable UDP inputs. This solution is not recommended since all data from the sending host(s) will be lost.  &lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 09 Nov 2012 07:02:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19173#M342</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-11-09T07:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19174#M343</link>
      <description>&lt;P&gt;We're also running out of memory, but have zero UDP inputs configured.  Could there be another source of the leak?  We increased our VM from 8GB to 16GB and splunkd used it up in two days.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2013 14:22:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19174#M343</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-05-13T14:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19175#M344</link>
      <description>&lt;P&gt;@richgalloway: Are you running the most recent 5.x version (5.0.2 as of now)? I would typically recommend to use the &lt;A href="http://www.splunk.com/goto/splunk"&gt;S.o.S app&lt;/A&gt; to track the &lt;A href="http://splunk-base.splunk.com/answers/38832/how-do-i-set-up-the-sos-app-to-monitor-splunks-system-resource-consumption"&gt;resource usage of Splunk processes&lt;/A&gt; and establish a clear pattern. With that information, you'll want to open a support case to get this investigated further.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2013 18:42:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19175#M344</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2013-05-13T18:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Memory usage increase in V5?</title>
      <link>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19176#M345</link>
      <description>&lt;P&gt;We disabled the Splunk Deployment Monitor app and our memory consumption has been flat ever since.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2013 11:50:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Memory-usage-increase-in-V5/m-p/19176#M345</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2013-06-05T11:50:39Z</dc:date>
    </item>
  </channel>
</rss>

