Splunk Enterprise

Incremental increase in memory usage

khj
Explorer

I installed Splunk Add-on for Google Cloud Platform and set it up like this, and it keeps increasing until the memory usage reaches 99% at around 15% per day. I haven't found any specific reason, but it's been happening since I set it up for collection in that app. Is there anything wrong with that app?

Splunk Add-on for Google Cloud Platform 4.7.2
Average daily collection: 10G

[Setting up]
input type : Cloud Pub/Sub Based Bucket
Number of Threads : 10
Interval: 0

[system env]
CPU: Intel (R) Xeon (R) Platinum 8488C, 8Cores
Memory : 32 G

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @khj 

Your server specs look more than enough to cover this and it seems the app is intended to be run with the interval=0 set as it runs continuously. I think the best approach here would be to file a support case at https://www.splunk.com/support because this is a Splunk supported app, they should hopefully be able to validate things and hopefully remediate either through settings updates or a fix to the app itself if required.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @khj 

Your server specs look more than enough to cover this and it seems the app is intended to be run with the interval=0 set as it runs continuously. I think the best approach here would be to file a support case at https://www.splunk.com/support because this is a Splunk supported app, they should hopefully be able to validate things and hopefully remediate either through settings updates or a fix to the app itself if required.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...