Getting Data In

1 out of 2 indexer has high RAM utilisation

mjm295
Path Finder

After out upgrade from 6.5 to 7.2 1 of 2 indexers has high ram utilisation. We are running Enterprise Security too.

Health Status from the search head is showing a yellow for splunkd - data forwarding (I assume to that indexer?)

Health status on that indexer is showing a Red for buckets.

The percentage of small of buckets created (60) over the last hour is very high and exceeded the red thresholds (50) for index=app_logs, and possibly more indexes, on this indexer

So I'm not sure why its creating lots of small buckets - is this related to how we setup inputs?

mjm295
Path Finder

indexes.conf for the bucket:

[app_logs]
homePath = $SPLUNK_DB/app_logs/db
coldPath = $SPLUNK_DB/app_logs/colddb
thawedPath = $SPLUNK_DB/app_logs/thaweddb
frozenTimePeriodInSecs = 31557600
disabled = 0

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...