Splunk Enterprise

High Memory on Indexers

dvohra
Explorer

Hi All,

I have recently upgraded Splunk memory to 64 GB. I am observing strange behavior that capacity is consuming 90% of the memory. I am seeing the same behavior for past one year where i have increased the RAM from 16 GB to 64 GB Now.

Most of the memory is cache. Can anyone let me know if this is normal behaviour of Indexers with High memory along with cache.

 

Tags (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you are starting splunk with systemd, then you must update it’s config to use new additional memory. Just disable and then enable boot start or directly edit systemd startup config. 

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...