Getting Data In

Splunk - Files/Directories being monitored

melvync
Observer

Hi,

i have inherited a splunk installation, done by a 3rd party.  We are currently using Splunk Enterprise version 8.0.2, with universal forwarders on a Solaris host (11.3) and 4 solaris zones on that host.

 

We are experiencing very high memory consumption and CPU usage on the host and respective zones, but a restart of the splunk daemon usually resolves  the memory issues.  We are currently restarting the splunk daemon's every 4-5 days.

When we do restart the splunk services, they jump to the top CPU users the moment it's started.

I have read that the high CPU could be attributed to the number of files/directories being monitored, so I ran the "splunk list monitor"  command on each zone being monitored and on the host, and found that certain directories were being monitored across all forwarders, even if those directories didn't exist on that zone.

I still don't know enough about splunk (am working through a pluralsight splunk fundamentals training course) to know whether  the list of files/directories to be monitored is being set at a zone/machine level or globally, and where I can go to find out.

Any assistance in this regard would be greatly appreciated.

thanks

Mel

Labels (2)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...