All Apps and Add-ons

Splunk on Splunk not matching to resources on server

sbattista09
Contributor

My indexers are running 6gb ram and 6 cores. In Splunk on Splunk under CPU/Memory Usage, the graphs for CPU Usage are showing CPU spikes over 600%. How would that be possible? I also see this for my Median Virtual Memory Usage. I see memory spikes over 7,000mb.

0 Karma
1 Solution

hexx
Splunk Employee
Splunk Employee

In the panels of the CPU/Memory Usage view, S.o.S expresses CPU usage per process class as a percentage of one CPU core. This means that a CPU usage of 600% is equivalent to 6 CPU cores used - in this case, 100% of system-wide CPU resources.

Virtual memory is typically inclusive of both physical memory (RAM) and swap (disk), which is why it is not unexpected to see it exceed the amount of physical memory installed.

Finally, as @javiergn points out, I strongly recommend to migrate from S.o.S to the Distributed Management Console to monitor your Splunk deployment.

View solution in original post

hexx
Splunk Employee
Splunk Employee

In the panels of the CPU/Memory Usage view, S.o.S expresses CPU usage per process class as a percentage of one CPU core. This means that a CPU usage of 600% is equivalent to 6 CPU cores used - in this case, 100% of system-wide CPU resources.

Virtual memory is typically inclusive of both physical memory (RAM) and swap (disk), which is why it is not unexpected to see it exceed the amount of physical memory installed.

Finally, as @javiergn points out, I strongly recommend to migrate from S.o.S to the Distributed Management Console to monitor your Splunk deployment.

sbattista09
Contributor

that was what i was thinking but needed to be sure before i forward with what i am trying to prove. thank you hexx!

0 Karma

javiergn
SplunkTrust
SplunkTrust

I know this is not the type of answer you are expecting but if you are running Splunk 6.2 or 6.3, why don't you use the Distributed Management Console instead?

The available dashboards provide insight into your deployment's or instance's

 search performance
 indexing performance
 operating system resource usage
 Splunk app key value store performance
 search head and indexer clustering
 index and volume usage
 forwarder connections
 and license usage.

sbattista09
Contributor

i do not see operating system resource usage in the DM.

0 Karma

hexx
Splunk Employee
Splunk Employee

Take a look at the Resource Usage: Machine view.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...