Deployment Architecture

Universal Forwarder

fumiaki
New Member

Windows OSにUniversal Forwarderを導入しています。
当該OS上で、定期的にCPUが高くなる事象が続いています。
定期的というのは、2個あり、15分毎、120分毎の2パターンです。
15分毎は、Splunkマネージャからの情報収集のためと判明しましたが、
120分毎にCPU使用率が高くなる(ほぼ張り付き)となる事象が見当つきません。
こちら、類似事例はございますでしょうか。

Universal Forwarder is introduced in Windows OS.
On this OS, the event that the CPU becomes high periodically continues.
There are two periodic, two patterns every 15 minutes, every 120 minutes.
Every 15 minutes it turned out to be for collecting information from Splunk manager,
I can not find the event that the CPU usage rate becomes high (almost sticking) every 120 minutes.
Are there similar cases here?

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...