Deployment Architecture

Health Check: Minimum System Requirements for Indexers

ahadghani
Engager

We are receiving messages about how our indexers (distributed environment) doesn't meet the minimum system requirements, but after taking a further look at Splunk's reference hardware documentation (https://docs.splunk.com/Documentation/Splunk/8.1.1/Capacity/Referencehardware) I still can't seem to figure out where we are lacking in. 

The message that I'm referring to is the following:

"Health Check: Splunk server "server_name" does not meet the recommended minimum system requirements."

This is currently what we're using for all three indexers:

64-bit Linux , 16 CPU cores,  and15.66 RAM. 

If anyone could provide some guidance on this matter that would be greatly appreciated! 

 

 

 

 

Labels (1)
0 Karma

aagro
Path Finder

I encountered the same problem after ES (7.3.0) installation and what Giuseppe say is correct about the RAM.
To avoid the issue edit alert "Audit - ES System Requirements" on SH ES and adjust the RAM value.
Splunk expect 32000MB RAM into the check but your system can report 31750MB as 32GB RAM.

Regards,

Antonio

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @ahadghani,

are you using the ES?

I found the same problem in one of my projects: Reference Hardware for Indexers with ES is 16 GM of RAM and I had 16 GB, but the health check is done on available memory that's a little less than 16 GB (in my case 15.88, in your case 15.66).

You have three solutions:

  • disabling the health check (I'd avoid!),
  • adding 1 GB of RAM ( the best if possible),
  • modify the health check search (the last choice) reducing the threeshold to 15.50.

In my project I had a physical Indexer so it wasn't possible to add RAM, so I modified the health check search.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...