Splunk Enterprise

Higher memory usage with 9.4.0 splunkd process.

hrawat
Splunk Employee
Splunk Employee

Apart from https://community.splunk.com/t5/Splunk-Enterprise/Linear-memory-growth-with-Splunk-9-4-0-and-above/m...
Some splunk instances(UF/HF/SH/IDX) might see higher memory usage after the upgrade.

hrawat_0-1740696908616.png

9.4.0 has introduced new active channel cache. It has a cache TTL of 3600 sec.

active_eligibility_age = <integer>
* The time, in seconds, after which splunkd removes an idle input
  channel from the active channel cache to free up memory.
* Default: 3600



Before 9.4.0, splunkd was using inactive channel cache. It had a cache ttl of 330 sec. It's not used anymore.

inactive_eligibility_age_seconds = <integer>
* Time, in seconds, after which an inactive input channel will be removed from
  the cache to free up memory.
* Default: 330



Because of high active channel cache TTL, splunkd memory footprint might be higher on some splunk deployments.

In limits.conf reduce active channel cache TTL to 330 ( 9.4.2 onwards, by default it's 330)

 

 

[input_channels]
active_eligibility_age = 330

 

 

 

 

Labels (1)
Tags (1)
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...