Monitoring Splunk

Splunk reports wrong cpu count

vanvan
Path Finder

Hi,

We are running Splunk on RedHat 7.x VMs and originally the VMs had 2 cpus with 2 cores each. In DMC and in REST service "| rest splunk_server=local /services/server/info" the output is that we have 4 cores in total. Recently we've upgraded the VMs to have 4 cpus and we were expecting to see that we'll have 8 cores available in total. But it doesn't seem so.

Any ideas why? We have restarted Splunkd and the whole VM. The outputs of linux commands in SSH like "lscpu" or "cat /proc/cpuinfo" show that there are 4 cpu's installed in the VM, but Splunkd still doesn't notice them...

Euphrates
Engager

I am experiencing identical problem. Haven't been able to find answer online nor get in contact with Splunk support. Splunk isn't noticing my extra cores after I upgraded instance. Now I'm having performance issues like hot buckets rolling prematurely and the speed of concurrent searches is suffering.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...