All Apps and Add-ons

Why is enabling Cisco ACI App for Splunk Enterprise creating a huge load on the APIC?

jasocoll
New Member

Cisco ACI APP for Splunk, when I enable this collection, it creates a huge load on the APIC.

[script://$SPLUNK_HOME/etc/apps/TA_cisco-ACI/bin/collect.py -classInfo aaaModLR faultRecord eventRecord]

I have attempted to widen the interval, but it just reduces the number of times the load happens. The APIC is almost unusable while this collection is happening.  I removed these one at a time, and it appears to be the poll of the eventRecord that is causing the drag on the APIC. I thought Splunk would only pull in the new information since the last poll, but that does not appear to be what is actually happening.  Is this expected? Is there a way to remedy this issue?

Labels (2)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...