Monitoring Splunk

number of splunkd processes rising

ctripod
Explorer

I have a linux host running 6.0.2 and I notice that the number of splunkd rising on one of my indexers. When the processes get above 100+ splunkd processes everything starts to suffer. Has anyone seen this? Under what circumstances does splunk start to spawn more processes?

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi ctripod,

normally there are three kind of splunkd processes around which can be shown by using the $SPLUNK_HOME/bin/splunk status command. You will get a list of PID's for the main Splunk process, Splunk Web process and Splunk helper processes.
Those helper processes are mainly your searches, so if you see the amount of helper processes raising means you run more searches. Form the command output you can use the PID and check what searches are running or you use the S.o.S app and check your searches from there.

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...