Getting Data In

Increased CPU on Universal Forwarder since v9

tradevine
Engager

We upgraded the Splunk Universal Forwarders on our web servers from 8.0.5 to 9.0.1 back in late October and since then we've seen a dramatic increase in CPU Utilization by the Splunkd.exe process on each server.

Each instance is tracking a fairly large amount of files - typically 3k or so per day and in a folder that can contain up to 10k files. I've found reducing the amount of 'old' files in the folder helps, but the CPU load is still dramatically above what it was with version 8.0.5.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...