Getting Data In

How to configure a Splunk 6.3.1 universal forwarder to prevent high CPU consumption?

omerr
Explorer

Hi,

I have about 1500 Universal Forwarders installed in our environment.
The UF version is 6.3.1 and installed on Windows computers.

Recently, I mentioned that the splunkd process (which related to the splunk UF service) uses about 30-60% of the machine CPU in constant all the time!

You can accept with me that this is unacceptable behavior .

The inputs.conf on the UF configure to monitor log files, windows event logs, performance logs and processes memory consumption.

One thing I have done for trying to fix it is to add the property of ignoreOlderThan = 120m for all the inputs in inputs.conf.

Unfortunately, this is not working as I expected and I still see the CPU of the UF very high (same as before).

What else I can do?
There is a way to limit the percent of the CPU consumption of UF?
There is maybe problem with UF 6.3.1 with CPU consumption?

Thanks for the supporting,

Omer Rudik.

0 Karma

YossiMarzuk
New Member

Hi,

I was able to manage the CPU and memory consumptions of the Splunk agent using Intigua.
I was facing with this issue on my Exchenge servers and using Intigua I was able to throlle the CPU and memory consumption.
You can download it here: http://www.intigua.com/get-intigua

Yossi Marzuk

0 Karma

akakjs
New Member

Have you tried disabling the recurse option on any monitor stanzas in inputs.conf?

I've had some issues with the 6.3.x forwarders and high cpu on using both the recurse option and wildcards in the monitor path. From my support requests it sounds like it's a known issue with short file names and there's a fix on the way.

Ben

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps the UF is collecting data too often. Try setting higher values for interval in the perfmon stanzas of the inputs.conf file.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...