Monitoring Splunk

Lots of Splunkd.exe processes

ARothman
Path Finder

I just found that my Windows server based Splunk console is running 14 splunkd.exe services simultaneously... is this due to the latest version of Splunk (5.0.1) or does this, possibly, have to do with the number of real-time alerts I have configured in the console? Overall, the processes aren't using that much CPU on the average (spikes here and there), but they are using almost a full gig of RAM on my server:

Tags (1)
0 Karma
1 Solution

sowings
Splunk Employee
Splunk Employee

Splunk forks a splunkd process (in your case, a .exe) to run each search. One of those processes will be the "main" splunkd, the rest will be as the result of a search, such as a dashboard, or the real time alerts you've described.

View solution in original post

sowings
Splunk Employee
Splunk Employee

Splunk forks a splunkd process (in your case, a .exe) to run each search. One of those processes will be the "main" splunkd, the rest will be as the result of a search, such as a dashboard, or the real time alerts you've described.

sowings
Splunk Employee
Splunk Employee

Note that "small searches on a short interval" can often serve as a "good enough" approximation to real-time searches / alerts. In this instance, the search process (splunkd.exe) would live long enough to complete the search, but would not persist after that. If the search only takes 10s to run, and it's run on a 5 minute basis, the overall memory and CPU footprints would be pretty small.

ARothman
Path Finder

Hrm... well, if that's the case, looks like I'll either be letting management know that we'll likely have to increase the RAM on this box if they want me to go ahead with creating dozens more real-time alerts... or those alerts simply can't be real-time 😄

Thanks for the confirmation.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...