Alerting

Splunk is showing high CPU load on Linux Server

4uramana4u
Explorer

Hello Splunk Experts,

I have an issue with measuring the CPU load in a Linux box. 

With the below query, I am getting a high CPU usage when there were no activities running on Linux Server.

Actually, the server status is pretty much an Idea most of the time and it is being used as a backup server.

cpu_load = 100 - PercentIdleTime;   

eval cpu_load = 100 - PercentIdleTime | stats avg(cpu_load) as "CPUUsage" by host | eval "CPUUsage"=round('CPUUsage', 2) | where CPUUsage>90

 

 

Labels (1)
Tags (1)
0 Karma

Pikta
Explorer

Hi,  @4uramana4u 
Can you write your Linux machine parameters? 
Maybe the answer in your question is here:

Splunk hardware requirements
The following are the minimum and recommended hardware requirements for running Splunk Light.

Platform : Non-Windows platforms 

Minimum supported hardware: 1x1.4 GHz CPU, 1 GB RAM

Recommended hardware :  2x six-core, 2+ GHz CPU, 12 GB RAM, Redundant Array of Independent Disks (RAID) 0 or 1+0, with a 64 bit OS installed.

0 Karma

4uramana4u
Explorer

@Pikta 

Thanks for the reply. 

The intended server is actually a Database server managing the production data and we want the CPU usage to be monitored by Splunk.

In terms of hardware, it is well equipped and it has nearly 1 million DB transactions per day. 

 

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...