Getting Data In

Optimising CPU + RAM usage on Universal Forwarder

DavidHourani
Super Champion

Hello guys,

I've been looking around in the questions and most of them are about forwarders causing High CPU because of some bug or some misconfiguration. My questions is about optimising and tweaking a universal forwarder that is working well in order to reduce its CPU impact.

So anyone who has tips and tricks to share it will be very much welcome. Even if you have system level tips for linux/windows it's also welcome!

Best regards,
David

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

I'm not sure there is a prefect answer for your question. By default, the fwd is designed to have a very limited impact on the system. You can limit the inputs to the ones that match your needs.
You might also look at windows system features.

Of course, you can monitor CPU usage in Splunk 🙂

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Hi David,

Do you have any specific issues ? On which system ? When collecting what kind of data ?
Can you give some details ?

0 Karma

DavidHourani
Super Champion

Hello Mathieu, hope you're well 🙂

I have FWDs running on windows DC and I want to set limits to make sure that they never go over 5% CPU even if that means slowing down log collection.
Any idea on how that could be done ?
Cheers,
David

0 Karma

robertlynch2020
Influencer

I have the same issues, do you find a solution

0 Karma

ddrillic
Ultra Champion

Good information at -

alt text

Search please for the forwarder parts...

0 Karma

DavidHourani
Super Champion

What do you mean ? did you post any link because I cant see anything 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...