Monitoring Splunk

number of splunkd processes rising

ctripod
Explorer

I have a linux host running 6.0.2 and I notice that the number of splunkd rising on one of my indexers. When the processes get above 100+ splunkd processes everything starts to suffer. Has anyone seen this? Under what circumstances does splunk start to spawn more processes?

Tags (1)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi ctripod,

normally there are three kind of splunkd processes around which can be shown by using the $SPLUNK_HOME/bin/splunk status command. You will get a list of PID's for the main Splunk process, Splunk Web process and Splunk helper processes.
Those helper processes are mainly your searches, so if you see the amount of helper processes raising means you run more searches. Form the command output you can use the PID and check what searches are running or you use the S.o.S app and check your searches from there.

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...