Getting Data In

Why are we seeing high memory usage with a Splunk 6.2.3 forwarder installed on a Windows server?

mattkun
New Member

We are currently having an issue with Splunk forwarder installed on a Windows server. It takes up a lot of memory utilization.

Any suggestion how to fix this? We are running Splunk 6.2.3. Help help. Thanks.

0 Karma

lguinn2
Legend

The amount of memory that a Splunk forwarder uses is directly related to the number of files that the forwarder is monitoring.

How many files is the forwarder monitoring? If you are not sure, log on the the machine and run

splunk list monitor

You may see that you are monitoring many files, including inactive files. The problem is that Splunk cannot be sure those files are inactive; it will continue to keep them in its list of files to monitor. If you can refine the stanzas in inputs.conf to monitor less - or remove the inactive files from the path that Splunk is monitoring - you will probably see an immediate reduction in the memory and CPU consumption. (You will have to restart the forwarder after making these changes.)

Of course, this is just a guess, based on not much information...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...