Hi All,
I have recently upgraded Splunk memory to 64 GB. I am observing strange behavior that capacity is consuming 90% of the memory. I am seeing the same behavior for past one year where i have increased the RAM from 16 GB to 64 GB Now.
Most of the memory is cache. Can anyone let me know if this is normal behaviour of Indexers with High memory along with cache.
If you are starting splunk with systemd, then you must update it’s config to use new additional memory. Just disable and then enable boot start or directly edit systemd startup config.
r. Ismo