Dashboards & Visualizations

high cpu and load usage

splukiee
Loves-to-Learn

splunk environments with High CPU usage 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

@kiran_panchavathas some good suggestions.  Also consider using post-processing  and/or saved searches in the dashboards to reduce CPU usage and speed up the dashboards.

---
If this reply helps you, Karma would be appreciated.

kiran_panchavat
SplunkTrust
SplunkTrust

@splukiee 

 

Certainly! Addressing high CPU usage in your Splunk environment due to specific dashboards can be challenging, but let’s explore some strategies to mitigate the issue:

Dashboard Optimization:-

Review Dashboard Components:

Inspect each dashboard panel. Are there any resource-intensive visualizations (e.g., complex charts, tables, or maps)? Simplify or optimize them.

Reduce Real-Time Updates:

If dashboards update in real-time, consider increasing the refresh interval. Frequent updates can strain CPU resources.

Limit Concurrent Sessions:

Since users have multiple sessions open, limit the number of concurrent sessions per user. Excessive sessions can overload the system.

Use Summary Indexes:

Consider using summary indexes for frequently accessed data. This reduces the need for real-time searches.

Monitoring and Troubleshooting:

Splunk Monitoring Console (MC): Use MC to monitor resource usage. Check the CPU Usage by process class graph to identify which components consume the most CPU.

https://lantern.splunk.com/Splunk_Platform/Product_Tips/Administration/Troubleshooting_high_resource... 

https://docs.splunk.com/Documentation/Splunk/9.2.0/DMC/ResourceusageCPU 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...