Splunk Enterprise

How to resolve Splunk Enterprise Poor Performance after installation of IT Essentials Work

shocko
Contributor

I'm running:

  • Splunk Enterprise 8.2.5 on Windows 2019.
  • 2 indexers in a cluster and a single search head and separate cluster master/license master/deployment server all on windows 2019. 

and have installed IT Essentials work version 4.31.1 and created the clustered indexes and enabled the apps I wish to use.  After a few mins the web interface on my single search head grinds to a halt and everything starts running very slowly. Compute on the search head and indexers seems fine and I have 32 cores and 64 GB RAM on each. If I disable all the apps that come with the IT Essentials work package performance returns to normal. 

Any ideas on where to look to troubleshoot this? 

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Exploring the OpenTelemetry Collector’s Kubernetes annotation-based discovery

We’ve already explored a few topics around observability in a Kubernetes environment -- Common Failures in a ...

Use ‘em or lose ‘em | Splunk training units do expire

Whether it’s hummus, a ham sandwich, or a human, almost everything in this world has an expiration date. And, ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...