Splunk Enterprise

High Memory on Indexers

dvohra
Explorer

Hi All,

I have recently upgraded Splunk memory to 64 GB. I am observing strange behavior that capacity is consuming 90% of the memory. I am seeing the same behavior for past one year where i have increased the RAM from 16 GB to 64 GB Now.

Most of the memory is cache. Can anyone let me know if this is normal behaviour of Indexers with High memory along with cache.

 

Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you are starting splunk with systemd, then you must update it’s config to use new additional memory. Just disable and then enable boot start or directly edit systemd startup config. 

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...