Getting Data In

Optimising CPU + RAM usage on Universal Forwarder

DavidHourani
Super Champion

Hello guys,

I've been looking around in the questions and most of them are about forwarders causing High CPU because of some bug or some misconfiguration. My questions is about optimising and tweaking a universal forwarder that is working well in order to reduce its CPU impact.

So anyone who has tips and tricks to share it will be very much welcome. Even if you have system level tips for linux/windows it's also welcome!

Best regards,
David

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

I'm not sure there is a prefect answer for your question. By default, the fwd is designed to have a very limited impact on the system. You can limit the inputs to the ones that match your needs.
You might also look at windows system features.

Of course, you can monitor CPU usage in Splunk 🙂

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Hi David,

Do you have any specific issues ? On which system ? When collecting what kind of data ?
Can you give some details ?

0 Karma

DavidHourani
Super Champion

Hello Mathieu, hope you're well 🙂

I have FWDs running on windows DC and I want to set limits to make sure that they never go over 5% CPU even if that means slowing down log collection.
Any idea on how that could be done ?
Cheers,
David

0 Karma

robertlynch2020
Influencer

I have the same issues, do you find a solution

0 Karma

ddrillic
Ultra Champion

Good information at -

alt text

Search please for the forwarder parts...

0 Karma

DavidHourani
Super Champion

What do you mean ? did you post any link because I cant see anything 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...