All Apps and Add-ons

Splunk DB Connect 2: Can input scheduling be improved to prevent CPU spikes?

matthijsk
Explorer

We use DB connect to import log data from several databases into Splunk. We want to do this every 60 seconds to keep Splunk up to date. We set this up and it worked fine, but once we did a reboot of the Splunk machine this was running on, we noticed spikes in CPU use every minute. All the inputs (that run every 60 seconds) now start at the same time (as is documented). This is very impractical and inefficient. We have solved this by giving each input a slightly different interval (like 60 seconds / 62 seconds / 64 seconds / etc). It would be more practical if we could either define a cron schedule in seconds (which is not supported in cron) or be able to define a delay for an input so it will not immediately start after a Splunk start ,but wait for a specific time. That would allow us to balance the inputs within a minute and thus balance load on the CPU.

woodcock
Esteemed Legend

Or the same thing for scheduling reports (a window) can be done for DB Connect, too.

0 Karma

neilhaywood
Engager

In case it helps.

We had a similar issue with opsec grabbing data every 30 seconds.

There was too much data to process, before the data was processed a new process was started, using up cpu.

We increased the time between grabbing the data to 300 seconds.

0 Karma

matthijsk
Explorer

Hi,

thank you for your comment. We prefer to get the data a little sooner as we have some alerting set up based on this data. Cannot do it continuously as the data in SQL should be updated within 60 seconds of being created.
Setting it up with different intervals has helped but is not a very intuitive solution.

Matthijs

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...