Getting Data In

How to limit the use of resources like memory and CPU by Universal Forwarder?

jfeitosa_real
Path Finder

I'm monitoring AD and DNS Server logs on Windows 2019 servers and Universal Forwarder has been the resource utilization offender.

Is it possible to limit the server's memory or CPU usage by UF?

I'm running UF version 8.2.1 Windows Server 2019, Splunk Enterprise 8.2.1 Linux_64.

The amount of DNS events is huge.

[monitor://C:\Windows\System32\Dns\dns*.log]

dns_logging.png

Thanks in advance.

James \0/

Labels (2)
Tags (1)
0 Karma

LeandroKopke
Explorer

Does anyone have any suggestions for this problem?

Tks

0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of the streaming infrastructure for Splunk APM and Splunk RUM in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...