Deployment Architecture

The average load on our linux heavyforwarder is around 20, what can I do to reduce it and will increasing core count help in ways ?

srampally
Path Finder

The average load on our linux heavyforwarder is around 20. what can i do to reduce it and will increasing core count help in ways ?

what should be the ideal load range on a linux server running splunk enterprise as a heavy forwarder.

Tags (1)
0 Karma

nickhills
Ultra Champion

Ha, an ideal server is one that runs at 99% all the time, but assuming your box does not have 20 cores, that is not ideal.

It depends on what is loading the box. Is it simply compute, in which case more cores will help, or do you have other constraints which are impacting on performance, such as memory, IO, network, or even loops and waits in scripts.

If you can give us an idea of what apps are running on it, we may be able to make some educated guesses, but as a general rule of thumb, more cores, should reduce the load average.

A shot in the dark, but the AWS TA fully configured to pull in all datasources is VERY heavy on the load avg. Dont run this alongside other apps if you can help it.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...