Monitoring Splunk

Memory use in HP-Ux

omlojoha
Engager

Does someone know how much memory and CPU the Splunk agent uses when installed under HP-Ux? And how does the Splunk Agent act when a HP-Ux server is used intensively.

Thx!

Tags (3)
0 Karma
1 Solution

Simeon
Splunk Employee
Splunk Employee

I am assuming you mean to ask the consumption of a Splunk instance when used in Forwarding mode. Memory consumption is mostly determined by the type of inputs you are monitoring. A non-active Splunk process should not utilize much more than a 100 MB of RAM when in a Forwarding mode. The light-forwarding mode offers the least overhead. If the system is actively monitoring large files, I would expect RAM usage to increase proportionately to the files themselves. As for CPU, this is also dictated by the type of inputs you are using.

View solution in original post

0 Karma

omlojoha
Engager

Whe only want to log syslog and who.

0 Karma

Simeon
Splunk Employee
Splunk Employee

If you can detail the types of inputs you will be configuring, that will allow for a better answer.

Simeon
Splunk Employee
Splunk Employee

I am assuming you mean to ask the consumption of a Splunk instance when used in Forwarding mode. Memory consumption is mostly determined by the type of inputs you are monitoring. A non-active Splunk process should not utilize much more than a 100 MB of RAM when in a Forwarding mode. The light-forwarding mode offers the least overhead. If the system is actively monitoring large files, I would expect RAM usage to increase proportionately to the files themselves. As for CPU, this is also dictated by the type of inputs you are using.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...