Splunk Enterprise

Higher memory usage with 9.4.0 splunkd process.

hrawat
Splunk Employee
Splunk Employee

Apart from https://community.splunk.com/t5/Splunk-Enterprise/Linear-memory-growth-with-Splunk-9-4-0-and-above/m...
Some splunk instances(UF/HF/SH/IDX) might see higher memory usage after the upgrade.

hrawat_0-1740696908616.png

9.4.0 has introduced new active channel cache. It has a cache TTL of 3600 sec.

active_eligibility_age = <integer>
* The time, in seconds, after which splunkd removes an idle input
  channel from the active channel cache to free up memory.
* Default: 3600



Before 9.4.0, splunkd was using inactive channel cache. It had a cache ttl of 330 sec. It's not used anymore.

inactive_eligibility_age_seconds = <integer>
* Time, in seconds, after which an inactive input channel will be removed from
  the cache to free up memory.
* Default: 330



Because of high active channel cache TTL, splunkd memory footprint might be higher on some splunk deployments.

In limits.conf reduce active channel cache TTL to 330 ( 9.4.2 onwards, by default it's 330)

 

 

[input_channels]
active_eligibility_age = 330

 

 

 

 

Labels (1)
Tags (1)
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...