Getting Data In

Hourly CPU spike on indexers

Kindred
Path Finder

Hey,

Is there some internal scheduled event on an indexer than runs every hour? We're seeing our average CPU go from 30-40% to 100% during about a 5-10 minute period every hour on the hour.

splunkd.log doesn't reveal anything.

Tags (3)
0 Karma

andykuhn
Path Finder

You may want to interrogate the splunk indexer's contributions to the _internal index as a timechart by SOURCE. The difference in log events by time should correspond to to your hourly CPU temper tantrum. Hopefully you can see a periodic difference in the number of events by source, which may help you identify events that only occur in this span.

Do you have any batch operations indexing data every hour....maybe being directed to only one indexer instead of being load-balanced?

0 Karma

Kindred
Path Finder

@bmacias84 - yes its definitely Splunk, I can see it consume cpu by watching 'top'

0 Karma

bmacias84
Champion

Are you sure its a Splunk process? If you are running nix server I would monitor all process with the Nix_TA or if a windows system windows_TA. Set the collection interval to 1min.

0 Karma

MuS
Legend

Hi Kindred,

install the S.o.S app it can help you finding the cause for those peaks.

cheers, MuS

0 Karma

MuS
Legend

S.o.S is usually installed on every Splunk install, so to check the SH best thing to do is install S.o.S on them as well

0 Karma

Kindred
Path Finder

Doh.. thanks @MuS, enabled it and can see at least it is searches that are causing the CPU spike, but I can't drill down to find out which search. The only searches it seems to list are those local to the indexer, not the distributed searches from the search head.

0 Karma

MuS
Legend

did you enable the cpu.sh input?

0 Karma

Kindred
Path Finder

Not having much luck with SoS, the CPU report is all blank for some reason. Not sure what else it can provide.

0 Karma

linu1988
Champion

if you are having hourly report searches or hourly monitoring of any large files then you will see the spike. No big deal

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...