All Apps and Add-ons

Splunk on Splunk not matching to resources on server

sbattista09
Contributor

My indexers are running 6gb ram and 6 cores. In Splunk on Splunk under CPU/Memory Usage, the graphs for CPU Usage are showing CPU spikes over 600%. How would that be possible? I also see this for my Median Virtual Memory Usage. I see memory spikes over 7,000mb.

0 Karma
1 Solution

hexx
Splunk Employee
Splunk Employee

In the panels of the CPU/Memory Usage view, S.o.S expresses CPU usage per process class as a percentage of one CPU core. This means that a CPU usage of 600% is equivalent to 6 CPU cores used - in this case, 100% of system-wide CPU resources.

Virtual memory is typically inclusive of both physical memory (RAM) and swap (disk), which is why it is not unexpected to see it exceed the amount of physical memory installed.

Finally, as @javiergn points out, I strongly recommend to migrate from S.o.S to the Distributed Management Console to monitor your Splunk deployment.

View solution in original post

hexx
Splunk Employee
Splunk Employee

In the panels of the CPU/Memory Usage view, S.o.S expresses CPU usage per process class as a percentage of one CPU core. This means that a CPU usage of 600% is equivalent to 6 CPU cores used - in this case, 100% of system-wide CPU resources.

Virtual memory is typically inclusive of both physical memory (RAM) and swap (disk), which is why it is not unexpected to see it exceed the amount of physical memory installed.

Finally, as @javiergn points out, I strongly recommend to migrate from S.o.S to the Distributed Management Console to monitor your Splunk deployment.

sbattista09
Contributor

that was what i was thinking but needed to be sure before i forward with what i am trying to prove. thank you hexx!

0 Karma

javiergn
SplunkTrust
SplunkTrust

I know this is not the type of answer you are expecting but if you are running Splunk 6.2 or 6.3, why don't you use the Distributed Management Console instead?

The available dashboards provide insight into your deployment's or instance's

 search performance
 indexing performance
 operating system resource usage
 Splunk app key value store performance
 search head and indexer clustering
 index and volume usage
 forwarder connections
 and license usage.

sbattista09
Contributor

i do not see operating system resource usage in the DM.

0 Karma

hexx
Splunk Employee
Splunk Employee

Take a look at the Resource Usage: Machine view.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...