Getting Data In

CPU usage using the lightforwarder

kkalmbach
Path Finder

I am using the light forwarder on AIX and running into high CPU usage (80-90% of a CPU).
We tracked it down to using ellipse in the monitor line in inputs.conf.
(even a "*" uses too much CPU).
We are using the ellipse so that we can deploy the same inputs.conf to several machines, each with a different directory path.

If we tighten it down to a single directory/file, things run great.

My question is:
Is there any way to have splunk traverse the directory tree less often (once a day or even less frequent), but still read files it already knows about in near real time?

I did not see anything in the doc about a setting like that.

mw
Splunk Employee
Splunk Employee

You should open a bug on this issue. You'd have to write your own script to look for new files.

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...