Getting Data In

NUMA aware support for Windows Universal Forwarder?

chrzz
Observer

When running the Universal Forwarder on a physical Windows server with multiple CPUs, it looks like the agent selects a random CPU that the Universal Forwarder collects performance metrics from. Sometimes it collects data from CPU #1, sometimes from CPU #2.

If I have two CPUs and a client process that is also not NUMA aware that uses all of the CPU usage on ONE of the CPUs, the Universal Forwarder might be "connected" to the other CPU and only collecting CPU metrics from a potentially idle CPU.

Is this a problem others observe or is it just me?

Labels (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...