How can I find out what is taking up the CPU on a search head? Yesterday the utilization was 20% on avg., and today it is 80%.
The default search app has 2 dashboards which will tell you CPU utilization issues related to indexing and searching. They can be accessed by:
http://
http://
Also, what version of Splunk are you using? I had similar issues when I upgraded from 4.2 to 4.3. Then I upgraded to 4.3.1 and the problem went away.
Install sos app on the Search-head, enable the ps_sos.sh scritped input.
It will collect measures cpu/memory per splunk process, you may be able to see the detail. (if this is splunkd, splunkweb, or user searches)
http://splunk-base.splunk.com/apps/29008/sos-splunk-on-splunk