Splunk Enterprise

Incremental increase in memory usage

khj
Explorer

I installed Splunk Add-on for Google Cloud Platform and set it up like this, and it keeps increasing until the memory usage reaches 99% at around 15% per day. I haven't found any specific reason, but it's been happening since I set it up for collection in that app. Is there anything wrong with that app?

Splunk Add-on for Google Cloud Platform 4.7.2
Average daily collection: 10G

[Setting up]
input type : Cloud Pub/Sub Based Bucket
Number of Threads : 10
Interval: 0

[system env]
CPU: Intel (R) Xeon (R) Platinum 8488C, 8Cores
Memory : 32 G

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi @khj 

Your server specs look more than enough to cover this and it seems the app is intended to be run with the interval=0 set as it runs continuously. I think the best approach here would be to file a support case at https://www.splunk.com/support because this is a Splunk supported app, they should hopefully be able to validate things and hopefully remediate either through settings updates or a fix to the app itself if required.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi @khj 

Your server specs look more than enough to cover this and it seems the app is intended to be run with the interval=0 set as it runs continuously. I think the best approach here would be to file a support case at https://www.splunk.com/support because this is a Splunk supported app, they should hopefully be able to validate things and hopefully remediate either through settings updates or a fix to the app itself if required.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...