Monitoring Splunk

Distributed Management Console Reporting incorrect amount of CPU cores for indexers

mikaelbje
Motivator

Distributed Management Console Reporting incorrect amount of CPU cores for indexers
This is seen in both Splunk 6.2.6 and Splunk 6.3.0

Environment 1

  • Virtual Search Head has 12 CPU cores according to cat /proc/cpuinfo - Splunk DMC reports 12 cores - CORRECT
  • Physical Indexer 1 has 16 CPU cores according to cat /proc/cpuinfo - Splunk DMC reports 8 cores - INCORRECT
  • Physical Indexer 2 has 16 CPU cores according to cat /proc/cpuinfo - Splunk DMC reports 8 cores - INCORRECT

Environment 2

  • Virtual Search Head has 8 CPU cores according to cat /proc/cpuinfo - Splunk DMC reports 8 cores - CORRECT
  • Physical Indexer 1 has 32 CPU cores according to cat /proc/cpuinfo - Splunk DMC reports 16 cores - INCORRECT
  • Physical Indexer 2 has 32 CPU cores according to cat /proc/cpuinfo - Splunk DMC reports 16 cores - INCORRECT

I checked the output of ps and could see the splunkd process running on all CPU cores, so my question is if this is just a cosmetic bug?

0 Karma
1 Solution

mikaelbje
Motivator

Doh. Turns out looking at cat /proc/cpuinfo isn't enough. It outputs sockets X cores per socket X threads, so 2 sockets with 8 cores each with 2 threads = 31(32) processors in cat /proc/cpuinfo. DMC is correct.

View solution in original post

0 Karma

mikaelbje
Motivator

Doh. Turns out looking at cat /proc/cpuinfo isn't enough. It outputs sockets X cores per socket X threads, so 2 sockets with 8 cores each with 2 threads = 31(32) processors in cat /proc/cpuinfo. DMC is correct.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...