Splunk Enterprise

How to resolve Splunk Enterprise Poor Performance after installation of IT Essentials Work

shocko
Contributor

I'm running:

  • Splunk Enterprise 8.2.5 on Windows 2019.
  • 2 indexers in a cluster and a single search head and separate cluster master/license master/deployment server all on windows 2019. 

and have installed IT Essentials work version 4.31.1 and created the clustered indexes and enabled the apps I wish to use.  After a few mins the web interface on my single search head grinds to a halt and everything starts running very slowly. Compute on the search head and indexers seems fine and I have 32 cores and 64 GB RAM on each. If I disable all the apps that come with the IT Essentials work package performance returns to normal. 

Any ideas on where to look to troubleshoot this? 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...