Monitoring Splunk

Memory use in HP-Ux

omlojoha
Engager

Does someone know how much memory and CPU the Splunk agent uses when installed under HP-Ux? And how does the Splunk Agent act when a HP-Ux server is used intensively.

Thx!

Tags (3)
0 Karma
1 Solution

Simeon
Splunk Employee
Splunk Employee

I am assuming you mean to ask the consumption of a Splunk instance when used in Forwarding mode. Memory consumption is mostly determined by the type of inputs you are monitoring. A non-active Splunk process should not utilize much more than a 100 MB of RAM when in a Forwarding mode. The light-forwarding mode offers the least overhead. If the system is actively monitoring large files, I would expect RAM usage to increase proportionately to the files themselves. As for CPU, this is also dictated by the type of inputs you are using.

View solution in original post

0 Karma

omlojoha
Engager

Whe only want to log syslog and who.

0 Karma

Simeon
Splunk Employee
Splunk Employee

If you can detail the types of inputs you will be configuring, that will allow for a better answer.

Simeon
Splunk Employee
Splunk Employee

I am assuming you mean to ask the consumption of a Splunk instance when used in Forwarding mode. Memory consumption is mostly determined by the type of inputs you are monitoring. A non-active Splunk process should not utilize much more than a 100 MB of RAM when in a Forwarding mode. The light-forwarding mode offers the least overhead. If the system is actively monitoring large files, I would expect RAM usage to increase proportionately to the files themselves. As for CPU, this is also dictated by the type of inputs you are using.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...