Getting Data In

Why would indexers in our indexer cluster suddenly start consuming 100% CPU?


We have an indexer clustering Splunk environment, and recently, all our indexers are consuming 100% CPU. Not sure what will be the issue.

Kindly suggest

Are you using Real-Time searches? This will totally lock 1 core on every server.
Have you recently started Accelerating searches? The Indexer CPU cost can add up very quickly and has a temporary "backfill" cost that is very noticeable.

