Monitoring Splunk

How can I check the CPU utilization of the SH / indexer from the search?

damucka
Builder

Hello,

I do not have access to the OS machines of the Splunk but I suspect the CPU bottleneck because my alert jobs are having 3 min lag between scheduling and dispatching. I would like to investigate it further.
Is there any way to query the internal index for the CPU utilization of the SH or indexer?

Kind Regards,
Kamil

Labels (3)
Tags (1)
0 Karma
1 Solution

aokur_splunk
Splunk Employee
Splunk Employee

Another good place to look for bottlenecks are in the monitoring console -> indexing -> performance -> indexing performance:deployment... then look for the queues at 90th percentile and see how much they are utilized... these indexing queues will fill up and cause performance issues, which is a good place to start troubleshooting.

next steps would be to see which sourcetypes are consuming the most resources and optimize them using props/transforms.

additionally alerting is triggered by your search-heads so make sure your sh resources are ok too, you can see them in a similar fashion in the monitoring console under search -> activity

View solution in original post

0 Karma

aokur_splunk
Splunk Employee
Splunk Employee

Another good place to look for bottlenecks are in the monitoring console -> indexing -> performance -> indexing performance:deployment... then look for the queues at 90th percentile and see how much they are utilized... these indexing queues will fill up and cause performance issues, which is a good place to start troubleshooting.

next steps would be to see which sourcetypes are consuming the most resources and optimize them using props/transforms.

additionally alerting is triggered by your search-heads so make sure your sh resources are ok too, you can see them in a similar fashion in the monitoring console under search -> activity

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...