Monitoring Splunk

Splunk Indexers Physicial memory usage high

ram254481493
Explorer

Hi , I am currently experiencing high memory usage on my indexers when i saw the memory usage , i saw a high amount of memory caches below,
total used free shared buffers cached
Mem: 516761 477169 39592 0 1158 457892
-/+ buffers/cache: 18117 498644
Swap: 51199 551 50648

How safe is it to clear buffers and cache ? If i clear caches is it will create any issue like deleting data make indexers down ?
I am thinking to clear it using these commands :
sync; echo 1 > /proc/sys/vm/drop_caches.
sync; echo 3 > /proc/sys/vm/drop_caches

Labels (3)
0 Karma

jtacy
Builder

Your memory usage looks normal for an indexer. You can clear the cache but it's going to quickly fill up again which is a good thing since it helps you avoid unnecessary disk I/O. Splunk will still be able to use the memory when needed. What kind of application problem are you experiencing?

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...