Monitoring Splunk

Why is my CPU core count wrong?

cwilmoth
Path Finder

We have recently switched our Splunk environment over to larger physical servers running 2 - Intel Xeon E5-2695 v3 processors each. These are 14 core processors, so each machine should be showing 28 cores. However, when I query the server info REST endpoint, it only shows 14 cores each. So I'm sure this is causing issues with performance since Splunk sets parameters based on number of cores. Also, our Enterprise Security app is complaining that the search head doesn't meet the minimum required specifications for hardware.

Please advise.

Thanks.

Tags (3)
0 Karma

cwilmoth
Path Finder

According to Splunk support, this will be fixed in the 6.3.5 release which is not out yet...

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

If you didnt get this resolved, can you open a ticket with support and let them run it through our diag tools..

0 Karma

jakeprevatt
New Member

Good question 😉

0 Karma
Get Updates on the Splunk Community!

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...