Getting Data In

CPU usage using the lightforwarder

kkalmbach
Path Finder

I am using the light forwarder on AIX and running into high CPU usage (80-90% of a CPU).
We tracked it down to using ellipse in the monitor line in inputs.conf.
(even a "*" uses too much CPU).
We are using the ellipse so that we can deploy the same inputs.conf to several machines, each with a different directory path.

If we tighten it down to a single directory/file, things run great.

My question is:
Is there any way to have splunk traverse the directory tree less often (once a day or even less frequent), but still read files it already knows about in near real time?

I did not see anything in the doc about a setting like that.

mw
Splunk Employee
Splunk Employee

You should open a bug on this issue. You'd have to write your own script to look for new files.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...