<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunkd is at 100% cpu, lag in indexing in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42135#M468</link>
    <description>&lt;P&gt;Inputs .conf file exists in the host and not in the indexer and this is for the specific host only  TA&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2017 14:07:55 GMT</pubDate>
    <dc:creator>arunsundaram</dc:creator>
    <dc:date>2017-06-15T14:07:55Z</dc:date>
    <item>
      <title>splunkd is at 100% cpu, lag in indexing</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42131#M464</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;Yesterday I noticed that there's a substantial lag in event indexing to the default index (main). When inspecting the processes on my machine, I noticed that a single splunkd process running at 100% cpu. &lt;/P&gt;

&lt;P&gt;I tried to restart splunk several time, but splunk gets to 100% cpu immediately and stays there.&lt;BR /&gt;
I've opened ticket at &lt;A href="mailto:support@splunk.com"&gt;support@splunk.com&lt;/A&gt;, but no response till now. &lt;BR /&gt;
After deleting the index and re-indexing things got back to normal. &lt;/P&gt;

&lt;P&gt;24h later I'm encountering the same problem. &lt;/P&gt;

&lt;P&gt;The machine splunk is running on has 16 CPUs, 8GB RAM. ~200MB of data is being indexed daily, and there's no significant search activity as well. &lt;/P&gt;

&lt;P&gt;Will appreciate any help with that. &lt;/P&gt;

&lt;P&gt;Oren.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2011 19:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42131#M464</guid>
      <dc:creator>oreni</dc:creator>
      <dc:date>2011-12-29T19:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd is at 100% cpu, lag in indexing</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42132#M465</link>
      <description>&lt;P&gt;Issue solved. &lt;/P&gt;

&lt;P&gt;The problem was that Splunk was monitoring more than 4000 log files which were already indexed. &lt;/P&gt;

&lt;P&gt;In inputs.conf, we simply added ignoreOlderThan = 2d which solved the problem. &lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2011 21:30:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42132#M465</guid>
      <dc:creator>oreni</dc:creator>
      <dc:date>2011-12-29T21:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd is at 100% cpu, lag in indexing</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42133#M466</link>
      <description>&lt;P&gt;Thanks for the solution.&lt;/P&gt;

&lt;P&gt;Changes made....Problem went away.&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2016 18:08:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42133#M466</guid>
      <dc:creator>campbells</dc:creator>
      <dc:date>2016-05-09T18:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd is at 100% cpu, lag in indexing</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42134#M467</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I assume this is not a Splunk indexer. right ?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2017 18:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42134#M467</guid>
      <dc:creator>ali_alnajjar_ve</dc:creator>
      <dc:date>2017-01-02T18:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd is at 100% cpu, lag in indexing</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42135#M468</link>
      <description>&lt;P&gt;Inputs .conf file exists in the host and not in the indexer and this is for the specific host only  TA&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 14:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42135#M468</guid>
      <dc:creator>arunsundaram</dc:creator>
      <dc:date>2017-06-15T14:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: splunkd is at 100% cpu, lag in indexing</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42136#M469</link>
      <description>&lt;P&gt;the inputs.conf file exists in the host and this change need to be made at the host level. this will not affect the indexing&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 14:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunkd-is-at-100-cpu-lag-in-indexing/m-p/42136#M469</guid>
      <dc:creator>arunsundaram</dc:creator>
      <dc:date>2017-06-15T14:08:51Z</dc:date>
    </item>
  </channel>
</rss>

