Getting Data In

Optimising CPU + RAM usage on Universal Forwarder

DavidHourani
Super Champion

Hello guys,

I've been looking around in the questions and most of them are about forwarders causing High CPU because of some bug or some misconfiguration. My questions is about optimising and tweaking a universal forwarder that is working well in order to reduce its CPU impact.

So anyone who has tips and tricks to share it will be very much welcome. Even if you have system level tips for linux/windows it's also welcome!

Best regards,
David

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

I'm not sure there is a prefect answer for your question. By default, the fwd is designed to have a very limited impact on the system. You can limit the inputs to the ones that match your needs.
You might also look at windows system features.

Of course, you can monitor CPU usage in Splunk 🙂

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Hi David,

Do you have any specific issues ? On which system ? When collecting what kind of data ?
Can you give some details ?

0 Karma

DavidHourani
Super Champion

Hello Mathieu, hope you're well 🙂

I have FWDs running on windows DC and I want to set limits to make sure that they never go over 5% CPU even if that means slowing down log collection.
Any idea on how that could be done ?
Cheers,
David

0 Karma

robertlynch2020
Influencer

I have the same issues, do you find a solution

0 Karma

ddrillic
Ultra Champion

Good information at -

alt text

Search please for the forwarder parts...

0 Karma

DavidHourani
Super Champion

What do you mean ? did you post any link because I cant see anything 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...