<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lots of Splunkd.exe processes in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20568#M231</link>
    <description>&lt;P&gt;Note that "small searches on a short interval" can often serve as a "good enough" approximation to real-time searches / alerts. In this instance, the search process (splunkd.exe) would live long enough to complete the search, but would not persist after that. If the search only takes 10s to run, and it's run on a 5 minute basis, the overall memory and CPU footprints would be pretty small.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Feb 2013 17:25:20 GMT</pubDate>
    <dc:creator>sowings</dc:creator>
    <dc:date>2013-02-05T17:25:20Z</dc:date>
    <item>
      <title>Lots of Splunkd.exe processes</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20565#M228</link>
      <description>&lt;P&gt;I just found that my Windows server based Splunk console is running 14 splunkd.exe services simultaneously... is this due to the latest version of Splunk (5.0.1) or does this, possibly, have to do with the number of real-time alerts I have configured in the console?  Overall, the processes aren't using that much CPU on the average (spikes here and there), but they are using almost a full gig of RAM on my server:&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://i.imgur.com/U7cvCD9.jpg" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 17:16:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20565#M228</guid>
      <dc:creator>ARothman</dc:creator>
      <dc:date>2013-02-05T17:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Splunkd.exe processes</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20566#M229</link>
      <description>&lt;P&gt;Splunk forks a splunkd process (in your case, a .exe) to run each search. One of those processes will be the "main" splunkd, the rest will be as the result of a search, such as a dashboard, or the real time alerts you've described.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 17:18:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20566#M229</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-02-05T17:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Splunkd.exe processes</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20567#M230</link>
      <description>&lt;P&gt;Hrm... well, if that's the case, looks like I'll either be letting management know that we'll likely have to increase the RAM on this box if they want me to go ahead with creating dozens more real-time alerts... or those alerts simply can't be real-time &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks for the confirmation.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 17:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20567#M230</guid>
      <dc:creator>ARothman</dc:creator>
      <dc:date>2013-02-05T17:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Lots of Splunkd.exe processes</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20568#M231</link>
      <description>&lt;P&gt;Note that "small searches on a short interval" can often serve as a "good enough" approximation to real-time searches / alerts. In this instance, the search process (splunkd.exe) would live long enough to complete the search, but would not persist after that. If the search only takes 10s to run, and it's run on a 5 minute basis, the overall memory and CPU footprints would be pretty small.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2013 17:25:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Lots-of-Splunkd-exe-processes/m-p/20568#M231</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2013-02-05T17:25:20Z</dc:date>
    </item>
  </channel>
</rss>

