Splunk Enterprise

High Memory on Indexers

dvohra
Explorer

Hi All,

I have recently upgraded Splunk memory to 64 GB. I am observing strange behavior that capacity is consuming 90% of the memory. I am seeing the same behavior for past one year where i have increased the RAM from 16 GB to 64 GB Now.

Most of the memory is cache. Can anyone let me know if this is normal behaviour of Indexers with High memory along with cache.

 

Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you are starting splunk with systemd, then you must update it’s config to use new additional memory. Just disable and then enable boot start or directly edit systemd startup config. 

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...