Getting Data In

How to see the right number of CPUs for my indexer in the Distributed Management Console?

hartfoml
Motivator

When I do this on my RHEL indexer:

lscpu | egrep 'Thread|Core|Socket|^CPU\('

I get these results:

*
CPU(s): 32
Thread(s) per core: 2
Core(s) per socket: 8
Socket(s): 2
*

Yet in the "Distributed Management Console", I see that my system has 16 CPU's.

Could this be slowing Splunk Processes down or is it just a bug with the "Distributed Management Console"?
I know that the "Thread(s) per core:" means hyper-threading.
Does Splunk not know how to use hyper-threading?

0 Karma
1 Solution

Masa
Splunk Employee
Splunk Employee

In v6.3 and v6.4, DMC didn't count it for some reason. I do not know why we didn't count hyper-threaded cores.
Splunkd itself identify number of virtual cores including hyper-threaded. splunkd.log shows how many virtual CPU cores in the system, and that number should include hyper-threaded cores.

In v6.5 DMC (Distributed Monitoring Console) should show number of virtual cores. When hyper-threaded, virtual core should be calculated accordingly.

View solution in original post

Masa
Splunk Employee
Splunk Employee

In v6.3 and v6.4, DMC didn't count it for some reason. I do not know why we didn't count hyper-threaded cores.
Splunkd itself identify number of virtual cores including hyper-threaded. splunkd.log shows how many virtual CPU cores in the system, and that number should include hyper-threaded cores.

In v6.5 DMC (Distributed Monitoring Console) should show number of virtual cores. When hyper-threaded, virtual core should be calculated accordingly.

richgalloway
SplunkTrust
SplunkTrust

Hyper-threading does not add cores as far as Splunk is concerned. The DMC is correct.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...