Monitoring Splunk

Splunk CPU provisioning and how to convince admins of Splunk requirements


Hi All,

Just wanted to see what ways you have done to convince administrators to give you the recommended Splunk CPUs when installed in a virtual environment.

I have encountered this 3 times in as many weeks when visiting client sites. One recent site the admins only gave the search heads one CPU inititally which was just ridiculous. We convinced them to up it to 4 but it is still in my opinion woefully inadequate.

The administrators stated we will watch the servers and if we see high usage we will increase the cores.

I explained to them that on startup Splunk will check how many cores it has available and throttle itself accordingly based on settings in limits.conf. The other argument is sure Splunk may run with low CPU usage 90% of the time but the other 10% of the time it needs that power for complex searches and analysis.

Short of artificially increasing usage until we get the cores required what methods have others used to convince VM administrators to give your Splunk installation the recommended CPU and memory sizes?

Tags (2)

Splunk Employee
Splunk Employee

Because of these issues splunk does not recommend using VMs. Having said that, the best way to convince any one is to monitor CPU usage after the SH is in production. You will know very quickly (based on load) if you are CPU bound or not. Make sure you have historical view the CPU levels an not just snapshots in time.

0 Karma

Esteemed Legend

If you do not get a good answer, contact your Splunk account/sales team; this is the kind of thing they are very good at doing (helping you justify why you need more/different Splunk). They care as much as you do that Splunk performance is good and configuring Search Heads like this makes Splunk look very bad when it should not.

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...